← back
CVE-2025-32706

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 2.1%● KEVCWE-20
Vexday Risk Score
51Attention
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 2.1%KEV simPoC Nuclei Metasploit Patch referenciado
Lifecycle
13 May 2025Active exploitation (CISA KEV)
13 May 2025Published on NVD
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A flaw in Windows' log file system driver allows someone with user access to gain administrative privileges on the computer. This happens because the driver doesn't properly check the data it receives.

Technical detail

Improper input validation in the Windows Common Log File System Driver (CLFS) permits an authenticated local attacker to achieve privilege escalation through crafted input. The vulnerability requires local access and valid user credentials; successful exploitation grants elevated (administrative) privileges.

Summary generated and translated by AI from the official description.
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →