⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2022-05-04.

CVE-2022-24521

Severity
7.8HIGH
EPSS
8.2%
top 7.78%
CISA KEV
KEVRansomware
Added 2022-04-13
Due 2022-05-04
Exploit
Exploited in wild
Active exploitation observed
Timeline
KEV addedApr 13
PublishedApr 15
KEV dueMay 4
Latest updateDec 21
CISA Required Action: Apply updates per vendor instructions.

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages34 packages

NVDmicrosoft/windows< 10.0.14393.5066+4
CVEListV5microsoft/windows_76.1.06.1.7601.25924
CVEListV5microsoft/windows_8.16.3.06.3.9600.20337
NVDmicrosoft/windows_10_1507< 10.0.10240.19265
NVDmicrosoft/windows_10_1607< 10.0.14393.5066

Patches

🔴Vulnerability Details

4
GHSA
GHSA-59qr-cc8f-v837: Windows Common Log File System Driver Elevation of Privilege Vulnerability2022-04-16
CVEList
Windows Common Log File System Driver Elevation of Privilege Vulnerability2022-04-15
VulnCheck
Microsoft Windows CLFS Driver Privilege Escalation Vulnerability2022
Project0
Project Zero RCA: CVE-2022-24521: Windows Common Log File System (CLFS) Logical-Error Vulnerability

📋Vendor Advisories

2
CISA
Microsoft Windows CLFS Driver Privilege Escalation Vulnerability2022-04-13
Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability2022-04-12

🕵️Threat Intelligence

7
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #1 – CVE-2022-24521)2023-12-21
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #5 – CVE-2023-28252)2023-12-21
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #4 – CVE-2023-23376)2023-12-21
Securelist
Kaspersky crimeware report: new ransomware and 1-day exploits2022-08-24
Securelist
Ransomware updates & 1-day exploits2022-08-24
CVE-2022-24521 (HIGH CVSS 7.8) | Windows Common Log File System Driv | cvebase.io