CVE-2024-49138highunder attackCWE-122

CVE-2024-49138: high-severity vulnerability in Microsoft Windows 10 Version 1507

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Published · Updated

81Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 26%
from disclosure to weapon36 days
Published on NVDDec 10
1st PoC+36d
CISA KEVDec 10
exploitation probability
26%top 2% of all CVEs
observed exploitation
yesCISA + VulnCheck
19 public exploit(s)
Action required by CISAfederal deadline: 2024-12-31

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

A flaw in Windows' Common Log File System Driver allows an attacker with local access to gain higher-level system privileges, potentially taking full control of the computer. This is dangerous because it lets a regular user become an administrator without authorization.

Technical detail

The vulnerability exists in the Windows Common Log File System Driver and allows local privilege escalation through improper handling of kernel-mode operations. An authenticated attacker can exploit this to execute arbitrary code with SYSTEM privileges, requiring local access but no special user interaction.

Summary generated and translated by AI from the official description.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.