CVE-2022-37969highunder attackransomwareCWE-787

CVE-2022-37969: high-severity vulnerability in Microsoft Windows 10 Version 1507

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Published · Updated

81Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 28%
from disclosure to weapon177 days
Published on NVDSep 13
1st PoC+177d
CISA KEV+1d
exploitation probability
28%top 2% of all CVEs
observed exploitation
yesCISA + VulnCheck
10 public exploit(s)
Action required by CISAfederal deadline: 2022-10-05

Apply updates per vendor instructions.

In short

A flaw in Windows' log file system driver allows an attacker with regular user access to gain administrator-level privileges on the system. This is dangerous because it lets attackers take complete control of the computer.

Technical detail

A buffer overflow (CWE-787) in the Common Log File System (CLFS) driver allows local privilege escalation through improper input validation. An authenticated local user can exploit this vulnerability to execute arbitrary code in kernel context and obtain SYSTEM privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.