HIGH
CVE-2021-36955
CVSS
7.8
KEV
Description
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Summary dbcve.org
CVE-2021-36955 is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) driver that allows a local attacker to gain elevated SYSTEM-level privileges by exploiting a flaw in kernel-mode driver handling.
Mitigation
Apply the Microsoft security update for CVE-2021-36955 via Windows Update or standalone patch deployment to remediate the CLFS driver vulnerability.
EPSS Score
4.04%
Probability of exploitation in next 30 days
90.2th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36955
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-36955
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36955
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.