← back
CVE-2022-37969

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 28.5%● KEVCWE-787
In short

A flaw in Windows' log file system driver allows an attacker with regular user access to gain administrator-level privileges on the system. This is dangerous because it lets attackers take complete control of the computer.

Technical detail

A buffer overflow (CWE-787) in the Common Log File System (CLFS) driver allows local privilege escalation through improper input validation. An authenticated local user can exploit this vulnerability to execute arbitrary code in kernel context and obtain SYSTEM privileges.

Summary generated and translated by AI from the official description.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →