← back
CVE-2022-24521

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 7.3%● KEVCWE-787
Vexday Risk Score
71High priority
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 7.3%KEV simPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
13 Apr 2022Active exploitation (CISA KEV)
15 Apr 2022Published on NVD
19 Feb 2026Public PoC
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A flaw in Windows' Common Log File System driver allows an attacker with local access to run malicious code with elevated privileges. This bypasses security protections and gives the attacker full control over the system.

Technical detail

Buffer overflow (CWE-787) in the CLFS driver allows local privilege escalation when a user interacts with specially crafted log file structures. An attacker with local access can trigger out-of-bounds memory writes to execute arbitrary code in kernel context.

Summary generated and translated by AI from the official description.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →