⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.. Due date: 2025-04-29.

CVE-2025-29824Use After Free in Microsoft Windows 10 Version 1507

CWE-416Use After Free34 documents15 sources
Severity
7.8HIGHNVD
EPSS
0.4%
top 39.76%
CISA KEV
KEVRansomware
Added 2025-04-08
Due 2025-04-29
Exploit
No known exploits
Timeline
PublishedApr 8
KEV addedApr 8
KEV dueApr 29
Latest updateFeb 2
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages26 packages

NVDmicrosoft/windows< 10.0.14393.7969+5
NVDmicrosoft/windows_10_1507< 10.0.10240.20978
NVDmicrosoft/windows_10_1607< 10.0.14393.7969
NVDmicrosoft/windows_10_1809< 10.0.17763.7136
NVDmicrosoft/windows_10_21h2< 10.0.19044.5737

🔴Vulnerability Details

3
CVEList
Windows Common Log File System Driver Elevation of Privilege Vulnerability2025-04-08
GHSA
GHSA-74mq-6c57-fxpx: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally2025-04-08
VulnCheck
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability2025

📋Vendor Advisories

3
Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability2025-04-08
CISA
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability2025-04-08
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (SciPy) — CVE-2023-298242025-01-15

🕵️Threat Intelligence

27
Greynoiseio
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates2026-02-02
Tenable
Patch Tuesday 2025 Year In Review2025-12-10
Securelist
IT threat evolution in Q2 2025. Non-mobile statistics2025-09-05
Securelist
Desktop and IoT threat report for Q2 20252025-09-05
Securelist
PipeMagic in 2025: How the backdoor operators’ tactics have changed2025-08-18
CVE-2025-29824 — Use After Free in Microsoft | cvebase