HIGH
CVE-2025-29824
CVSS
7.8
KEV
Description
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Summary dbcve.org
Use-After-Free vulnerability in the Windows Common Log File System (CLFS) driver allows a locally authorized attacker to elevate privileges to higher permission levels by exploiting memory corruption in the kernel-mode driver.
Mitigation
Apply the Microsoft security update for CVE-2025-29824 via Windows Update or manual patch deployment to address the vulnerability in the CLFS driver.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
13.9%
Probability of exploitation in next 30 days
96.4th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29824
Vendor Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-29824-windows-common-log-file-system-driver-elevation-of-privilege-vulnerability-detection-script
Exploit, Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-29824-windows-common-log-file-system-driver-elevation-of-privilege-vulnerability-mitigation-script
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-29824
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.