Junglewise Threat Intelligence

CVE-2026-20820: Microsoft Windows CLFS Driver heap overflow privilege escalation

CVE-2026-20820 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows Server 2008 R2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Common Log File System (CLFS) Driver, a component that manages data logging for the operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Windows Common Log File System (CLFS) driver. The flaw is triggered when the driver improperly handles objects in memory, allowing a locally authenticated attacker with low privileges to execute code with SYSTEM-level permissions. The attack vector is local, requiring the attacker to run a specially crafted application on the target machine. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2008 R2 Service Pack 1

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats