CVE-2021-36955: high-severity vulnerability in Microsoft Windows 10 Version 1507
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
A flaw in Windows' Common Log File System driver allows an attacker with local access to bypass security restrictions and gain higher privileges on the system. This could let them take full control of the computer.
An elevation of privilege vulnerability in the Windows CLFS driver (Kernel component) that can be exploited via local access to escalate from a lower-privileged user context to system-level privileges. Requires prior local code execution; successful exploitation results in SYSTEM-level access.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.