Executive brief
A security vulnerability has been identified in the Windows Common Log File System (CLFS) Driver, a component that manages data logging for the operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in the Windows Common Log File System (CLFS) driver. The flaw is triggered when the driver improperly handles objects in memory, allowing a locally authenticated attacker with low privileges to execute code with SYSTEM-level permissions. The attack vector is local, requiring the attacker to run a specially crafted application on the target machine. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2008 R2 Service Pack 1
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory