HIGH

CVE-2025-32706

Microsoft Windows 10 1507 2025-05-13 CVSS v3.1
CVSS
7.8
KEV

Description

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Summary dbcve.org

A flaw in Windows Common Log File System Driver (CLFS.sys) allows improper input validation that can be exploited by an authenticated local attacker to escalate privileges to higher integrity levels. The vulnerability resides in how the driver handles input data, enabling a local attacker to execute code with elevated permissions.

Mitigation

Apply the relevant Windows security update (KB) for this vulnerability through Windows Update or enterprise patch management systems. Prioritize patching on systems where untrusted local users have access.

Proof of Concept

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

2.29%
Probability of exploitation in next 30 days
82.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE