CVE-2021-43226
published 2021-12-15CVE-2021-43226: Windows Common Log File System Driver Elevation of Privilege Vulnerability
PriorityP185high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2025-10-27
Exploited in the wild
EPSS
3.07%
86.3th percentile
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19145 | 10.0.10240.19145 |
| microsoft | windows_10_1607 | < 10.0.14393.4825 | 10.0.14393.4825 |
| microsoft | windows_10_1809 | < 10.0.17763.2366 | 10.0.17763.2366 |
| microsoft | windows_10_1909 | < 10.0.18363.1977 | 10.0.18363.1977 |
| microsoft | windows_10_2004 | < 10.0.19041.1415 | 10.0.19041.1415 |
| microsoft | windows_10_20h2 | < 10.0.19042.1415 | 10.0.19042.1415 |
| microsoft | windows_10_21h1 | < 10.0.19043.1415 | 10.0.19043.1415 |
| microsoft | windows_10_21h2 | < 10.0.19044.1415 | 10.0.19044.1415 |
| microsoft | windows_10_version_1507 | >= 10.0.0 < 10.0.10240.19145 | 10.0.10240.19145 |
| microsoft | windows_10_version_1607 | >= 10.0.0 < 10.0.14393.4825 | 10.0.14393.4825 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2366 | 10.0.17763.2366 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1977 | 10.0.18363.1977 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.1415 | 10.0.19041.1415 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1415 | 10.0.19042.1415 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1415 | 10.0.19043.1415 |
| microsoft | windows_10_version_21h2 | >= 10.0.0 < 10.0.19044.1415 | 10.0.19044.1415 |
| microsoft | windows_11_21h2 | < 10.0.22000.376 | 10.0.22000.376 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.376 | 10.0.22000.376 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25796 | 6.1.7601.25796 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25796 | 6.1.7601.25796 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20207 | 6.3.9600.20207 |
| microsoft | windows_server_2004 | < 10.0.19041.1415 | 10.0.19041.1415 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < 6.1.7601.25796 | 6.1.7601.25796 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < 6.1.7601.25796 | 6.1.7601.25796 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2021-43226 targets the Windows Common Log File System (CLFS) Driver and allows local privilege escalation; monitor for unexpected CLFS driver interactions or privilege escalation from low-privileged processes. ↗
- →Microsoft rates exploitation of CVE-2021-43226 as 'More Likely' for both latest and older software releases; prioritize detection on unpatched Windows endpoints across a wide range of versions (Windows 7 through Windows 11, Server 2008 through Server 2022). ↗
- ·No public exploit code or active exploitation confirmed at time of advisory; however, CISA added this to the Known Exploited Vulnerabilities catalog with a remediation due date, indicating later confirmed exploitation. ↗
- ·The vulnerability affects a very broad range of Windows versions; detection and patching scope should cover Windows 7 SP1 through Windows 11 and Windows Server 2008 SP2 through Server 2022. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w3v4-69ph-pfjp: Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43226
ghsa_unreviewed·2021-12-16·CVSS 7.8
CVE-2021-43207 [HIGH] CWE-269 GHSA-w3v4-69ph-pfjp: Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43226
Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43226.
GHSA
GHSA-98jh-5xvm-p5ph: Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43207
ghsa_unreviewed·2021-12-16·CVSS 7.8
CVE-2021-43226 [HIGH] CWE-269 GHSA-98jh-5xvm-p5ph: Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43207
Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43207.
VulnCheck
Microsoft Windows Privilege Escalation Vulnerability
vulncheck·2021·CVSS 7.8
CVE-2021-43226 [HIGH] Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247514973&idx=2&sn=0776f8f83c032c4d7433a567270a7ee1&source=41#wechat_redirect; https://cloud.google.com/blog/topics/threat-intelligence/ransomware-attacks-surge-rely-on-public-legitimate-tools; https://www.cisa.gov/sites/default/files/
CISA
Microsoft Windows Privilege Escalation Vulnerability
cisa·2025-10-06·CVSS 7.8
CVE-2021-43226 [HIGH] Microsoft Windows Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43226 ; https://nvd.nist.gov/vuln/detail/CVE-2021-43226
Remediation Due Date: 2025-10-27
Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability
vendor_msrc·2021-12-14·CVSS 7.8
CVE-2021-43226 [HIGH] Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver: Windows Common Log File System Driver
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5008218
Reference: https://support.microsoft.com/help/5008218
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5008206
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5008212
Reference: https://support.microsoft.com/help/5008212
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5008223
R
No detection rules found.
No public exploits indexed.
Zscaler
Zscaler found Windows Security Vulnerabilities | 12-14-2021
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found Windows Security Vulnerabilities | 12-14-2021
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Recorded Future
October 2025 CVE Landscape
blogs_recorded_future·CVSS 9.8
[CRITICAL] October 2025 CVE Landscape
# October 2025 CVE Landscape: 32 High-Impact Vulnerabilities Demand Immediate Attention
October 2025 saw a significant escalation in vulnerability activity, with Recorded Future's Insikt Group® identifying 32 high-impact vulnerabilities, double the 16 identified in September's CVE report. Twenty-six of these vulnerabilities scored as Very Critical.
What security teams need to know:
- Microsoft dominates: Eight of 32 vulnerabilities affect Microsoft products, including a critical WSUS deserialization flaw (CVE-2025-59287) now being actively exploited
- CL0P ransomware group exploited an Oracle E-Business Suite zero-day (CVE-2025-61882) for data theft and extortion campaigns
- Legacy vulnerabilities persist: Five of the 14 RCE-enabling vulnerabilities are over a decade old, highlighting c
2021-12-15
Published
2025-10-06
Added to CISA KEV
Exploited in the wild