← back
CVE-2022-24521

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 7.3%● KEVCWE-787
In short

A flaw in Windows' Common Log File System driver allows an attacker with local access to run malicious code with elevated privileges. This bypasses security protections and gives the attacker full control over the system.

Technical detail

Buffer overflow (CWE-787) in the CLFS driver allows local privilege escalation when a user interacts with specially crafted log file structures. An attacker with local access can trigger out-of-bounds memory writes to execute arbitrary code in kernel context.

Summary generated and translated by AI from the official description.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →