HIGH
CVE-2025-32706
CVSS
7.8
KEV
Description
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Summary dbcve.org
A flaw in Windows Common Log File System Driver (CLFS.sys) allows improper input validation that can be exploited by an authenticated local attacker to escalate privileges to higher integrity levels. The vulnerability resides in how the driver handles input data, enabling a local attacker to execute code with elevated permissions.
Mitigation
Apply the relevant Windows security update (KB) for this vulnerability through Windows Update or enterprise patch management systems. Prioritize patching on systems where untrusted local users have access.
Weakness (CWE)
CWE-20
Improper Input Validation
EPSS Score
2.29%
Probability of exploitation in next 30 days
82.5th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32706
Vendor Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-32706-detection-script-elevation-of-privilege-vulnerability-in-microsoft-windows-common-log-file-system-driver
Exploit, Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-32706-mitigation-script-elevation-of-privilege-vulnerability-in-microsoft-windows-common-log-file-system-driver
Exploit, Mitigation, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32706
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.