HIGH
CVE-2025-32701
CVSS
7.8
KEV
Description
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Summary dbcve.org
Use-after-free vulnerability in Windows Common Log File System (CLFS) driver allows a locally authenticated attacker to execute arbitrary code in kernel context and elevate privileges to SYSTEM level.
Mitigation
Apply Microsoft security updates (KB patches) for Windows systems as they become available; prioritize endpoints given the local attack vector.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
1.39%
Probability of exploitation in next 30 days
71.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.