← back
CVE-2022-37969

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 28.5%● KEVCWE-787
Vexday Risk Score
76High priority
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 28.5%KEV simPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
13 Sep 2022Published on NVD
14 Sep 2022Active exploitation (CISA KEV)
09 Mar 2023Public PoC
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A flaw in Windows' log file system driver allows an attacker with regular user access to gain administrator-level privileges on the system. This is dangerous because it lets attackers take complete control of the computer.

Technical detail

A buffer overflow (CWE-787) in the Common Log File System (CLFS) driver allows local privilege escalation through improper input validation. An authenticated local user can exploit this vulnerability to execute arbitrary code in kernel context and obtain SYSTEM privileges.

Summary generated and translated by AI from the official description.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →