Privilege Escalation Vulnerability in Windows Common Log File System (CLFS) Driver

CVE-2022-37969

Discovered: September 13th, 2022

Impacted Tech:

Windows Common Log File System (CLFS)

Attacker Location: Local

Highlights:

A vulnerability (which has been actively exploited) in the Windows Common Log File System allows attackers to obtain the highest level of access, known as system privileges.

This vulnerability exists when the attacker uses the exploit code which has been publicly made available, but the attacker must already have access to a compromised device, or the ability to run code on the target system.

Remediation:

Microsoft released fixes for this vulnerability as part of their regularly scheduled monthly release of security fixes, September 2022; “Patch Tuesday”.

References:

Microsoft Security Response Center – 37969

Leave a comment