Executive brief
A security vulnerability exists in the Windows Common Log File System (CLFS) driver, a core component that manages system logs. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This would allow them to bypass security restrictions, access sensitive data, or install malicious software.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in the Windows Common Log File System (CLFS) driver (clfs.sys). The flaw is triggered when the driver improperly handles log files or metadata in memory. To exploit this, an attacker must first have local access to the system with low-privileged user credentials. Successful exploitation allows the attacker to execute code with SYSTEM privileges, leading to a full compromise of the host. Microsoft has released security updates to address this issue via the MSRC Update Guide.
Affected products
- Microsoft Windows All supported versions of Windows
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory