CVE-2022-37969: high-severity vulnerability in Microsoft Windows 10 Version 1507
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
A flaw in Windows' log file system driver allows an attacker with regular user access to gain administrator-level privileges on the system. This is dangerous because it lets attackers take complete control of the computer.
A buffer overflow (CWE-787) in the Common Log File System (CLFS) driver allows local privilege escalation through improper input validation. An authenticated local user can exploit this vulnerability to execute arbitrary code in kernel context and obtain SYSTEM privileges.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.