Junglewise Threat Intelligence

CVE-2025-32701: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

CVE-2025-32701 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-05-13

Technologies: Microsoft Windows, Microsoft Windows 11, Microsoft Windows Server, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability in the Microsoft Windows Common Log File System (CLFS) Driver allows an authorized local attacker to elevate privileges. The vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019, 2022, 2025

Timeline

  • 2025-05-13: disclosed
  • 2025-05-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats