Junglewise Threat Intelligence

CVE-2026-40397: Microsoft Windows CLFS Driver privilege escalation

CVE-2026-40397 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows, Microsoft Windows Server 2012, Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Common Log File System (CLFS) driver, a core component used by the operating system for data logging. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows Common Log File System (CLFS) Driver (clfs.sys). The flaw is rooted in an integer underflow (CWE-191) during the processing of log files, which leads to a memory corruption condition. An attacker with low-privileged local access can exploit this by crafting a malicious log file to trigger the overflow. Successful exploitation allows the attacker to execute code with SYSTEM privileges, effectively gaining full control over the affected host. Microsoft has released security updates to address this issue across supported versions of Windows and Windows Server.

Affected products

  • Microsoft Windows Windows 10, Windows 11, Windows Server 2012, 2016, 2019, 2022

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Initial advisory published by Microsoft
  • 2026-06-01: other: Advisory updated to clarify vulnerability class as heap-based buffer overflow

References

Related threats