Junglewise Threat Intelligence

CVE-2026-50697: Microsoft Windows CLFS Driver privilege escalation

CVE-2026-50697 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Common Log File System (CLFS) Driver, a core component of the Windows operating system used for data and event logging. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could allow them to view sensitive data, install programs, or change system settings, potentially leading to a complete compromise of the affected machine.

Technical details

A privilege escalation vulnerability exists in the Windows Common Log File System (CLFS) Driver due to the exposure of sensitive information to unauthorized actors (CWE-200). An attacker with local access and low-level user privileges can exploit this vulnerability to gain elevated system privileges. The attack vector is local, requiring the attacker to execute a specially crafted application on the target system. Successful exploitation grants the attacker high confidentiality, integrity, and availability impacts, effectively allowing full system control. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Version 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All versions including Server Core

Timeline

  • 2026-07-14: advisory: Initial advisory published by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available by Microsoft

References

Related threats