CVE-2021-36955highunder attackransomware

CVE-2021-36955: high-severity vulnerability in Microsoft Windows 10 Version 1507

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Published · Updated

71Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 4.1%
from disclosure to weapon306 days
Published on NVDSep 15
1st PoC+306d
CISA KEV+49d
exploitation probability
4.1%top 10% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

A flaw in Windows' Common Log File System driver allows an attacker with local access to bypass security restrictions and gain higher privileges on the system. This could let them take full control of the computer.

Technical detail

An elevation of privilege vulnerability in the Windows CLFS driver (Kernel component) that can be exploited via local access to escalate from a lower-privileged user context to system-level privileges. Requires prior local code execution; successful exploitation results in SYSTEM-level access.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.