HIGH
CVE-2022-24521
CVSS
7.8
KEV
Description
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Summary dbcve.org
CVE-2022-24521 is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) driver. The vulnerability allows a locally authenticated attacker to gain elevated system privileges by exploiting a flaw in the kernel-mode driver. This is a high-severity local privilege escalation issue affecting Windows systems.
Mitigation
Apply the Microsoft security update for CVE-2022-24521 via Windows Update or by deploying the relevant security patch from Microsoft's February 2022 security bulletin. Prioritize patching systems with interactive user access.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
7.13%
Probability of exploitation in next 30 days
94th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.