← back
CVE-2024-49138

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 25.4%● KEVCWE-122
Vexday Risk Score
76High priority
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 25.4%KEV simPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
10 Dec 2024Active exploitation (CISA KEV)
10 Dec 2024Published on NVD
15 Jan 2025Public PoC
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A flaw in Windows' Common Log File System Driver allows an attacker with local access to gain higher-level system privileges, potentially taking full control of the computer. This is dangerous because it lets a regular user become an administrator without authorization.

Technical detail

The vulnerability exists in the Windows Common Log File System Driver and allows local privilege escalation through improper handling of kernel-mode operations. An authenticated attacker can exploit this to execute arbitrary code with SYSTEM privileges, requiring local access but no special user interaction.

Summary generated and translated by AI from the official description.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →