HIGH

CVE-2022-24521

Microsoft Windows 10 1507 2022-04-15 CVSS v3.1
CVSS
7.8
KEV

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Summary dbcve.org

CVE-2022-24521 is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) driver. The vulnerability allows a locally authenticated attacker to gain elevated system privileges by exploiting a flaw in the kernel-mode driver. This is a high-severity local privilege escalation issue affecting Windows systems.

Mitigation

Apply the Microsoft security update for CVE-2022-24521 via Windows Update or by deploying the relevant security patch from Microsoft's February 2022 security bulletin. Prioritize patching systems with interactive user access.

Patch Commit

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

7.13%
Probability of exploitation in next 30 days
94th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE