Executive brief
An out-of-bounds write vulnerability in the Microsoft Windows Common Log File System (CLFS) driver allows a local attacker to gain SYSTEM privileges. The flaw exists in how the driver handles objects in memory, leading to an elevation of privilege.
Affected products
- Microsoft Windows 10 versions up to (excluding) 10.0.10240.19444
- Microsoft Windows 11 versions up to (excluding) 10.0.22000.978
- Microsoft Windows Server 2022 versions up to (excluding) 10.0.20348.1006
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
Timeline
- 2022-09-14: disclosed
- 2022-09-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-09-14: patched: Microsoft released security updates to address this vulnerability.