← back
CVE-2025-29824

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 18.0%● KEVCWE-416
In short

A flaw in Windows' logging system allows an authorized user to gain higher privileges on their computer. The vulnerability occurs when the system tries to use memory that was already freed, which an attacker can exploit to run code with administrative rights.

Technical detail

Use-after-free vulnerability in the Windows Common Log File System Driver (CLFS) allows an authenticated local attacker to execute arbitrary code with elevated privileges. The attack requires prior local access and knowledge of the freed memory patterns; successful exploitation results in privilege escalation from user to kernel context.

Summary generated and translated by AI from the official description.
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →