⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2022-24481

Severity
7.8HIGH
EPSS
44.0%
top 2.46%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedApr 15
Latest updateApr 16

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages27 packages

CVEListV5microsoft/windows_76.1.06.1.7601.25924
CVEListV5microsoft/windows_8.16.3.06.3.9600.20337
CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.23679
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.5066
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.2803

🔴Vulnerability Details

3
GHSA
GHSA-fcmw-94mj-87r8: Windows Common Log File System Driver Elevation of Privilege Vulnerability2022-04-16
CVEList
Windows Common Log File System Driver Elevation of Privilege Vulnerability2022-04-15
VulnCheck
Windows Common Log File System Driver Elevation of Privilege Vulnerability2022

📋Vendor Advisories

1
Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability2022-04-12
CVE-2022-24481 (HIGH CVSS 7.8) | Windows Common Log File System Driv | cvebase.io