⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2021-11-17.

CVE-2021-36955

Severity
7.8HIGH
EPSS
20.6%
top 4.41%
CISA KEV
KEVRansomware
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedSep 15
KEV addedNov 3
KEV dueNov 17
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages33 packages

NVDmicrosoft/windows< 10.0.19041.1237+5
CVEListV5microsoft/windows_76.1.06.1.7601.25712
CVEListV5microsoft/windows_8.16.3.06.3.9600.20120
NVDmicrosoft/windows_10_1507< 10.0.10240.19060
NVDmicrosoft/windows_10_1607< 10.0.14393.4651

Patches

🔴Vulnerability Details

3
GHSA
GHSA-g26f-6mx8-j24w: Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-36963, CVE-2021-386332022-05-24
CVEList
Windows Common Log File System Driver Elevation of Privilege Vulnerability2021-09-15
VulnCheck
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability2021

📋Vendor Advisories

2
CISA
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability2021-11-03
Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability2021-09-14
CVE-2021-36955 (HIGH CVSS 7.8) | Windows Common Log File System Driv | cvebase.io