Executive brief
A security vulnerability exists in the Microsoft Windows component responsible for managing system logs. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This type of vulnerability is often used by sophisticated actors to deepen their foothold in a network after an initial breach.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Microsoft Windows Common Log File System (CLFS) Driver. The flaw is triggered when the driver improperly handles objects in memory, allowing a local authenticated attacker to execute code with SYSTEM privileges. While the vulnerability is categorized as an out-of-bounds read, Microsoft classifies the impact as Elevation of Privilege (EoP). This vulnerability has been observed being exploited in the wild and is included in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patches are available through standard Microsoft security updates.
Affected products
- Microsoft Windows Windows 10, Windows 11, Windows Server 2008, 2012, 2016, 2019, 2022
Timeline
- 2023-11-21: disclosed: Initial disclosure by Microsoft
- 2026-04-13: kev added: Added to CISA Known Exploited Vulnerabilities catalog