CVE-2019-1214
KEVmassLocal Privilege Escalation in Microsoft Windows CLFS Driver (CVE-2019-1214)
CISA: Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability
CVE-2019-1214 is an elevation of privilege flaw in the Windows Common Log File System (CLFS) driver, which improperly handles objects in memory (CWE-119). It is triggered locally: an attacker who can already execute low-privileged code on a vulnerable Windows machine can induce the driver's faulty memory handling, without any user interaction. Successful exploitation escalates the attacker's privileges on the host, yielding high impact to confidentiality, integrity and availability (effectively kernel/SYSTEM-level access). Affected systems span essentially the entire mainstream Windows install base at the time: Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 1903, and Windows Server versions 1803 and 1903. The flaw was patched in the September 2019 Patch Tuesday release, which Microsoft flagged as one of two privilege escalation bugs actively exploited in attacks, and it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03; no public PoC is known.
What to do: Apply Microsoft's September 2019 (or later) cumulative/monthly rollup security updates across all affected Windows 7, 8.1, RT 8.1, Windows 10 (1507–1903) and Windows Server 1803/1903 systems, using ESU updates for extended-support Windows 7/8.1 hosts. Since this is a local privilege escalation listed in CISA KEV, prioritize patching multi-user, internet-reachable hosts such as RDS/terminal servers and VDI where unprivileged users can run code. Verify the September 2019 update is installed and monitor for local privilege escalation activity.
| microsoft Windows 10 | 1507, 1607, 1703, 1709, 1803, 1809, 1903 |
| microsoft Windows 7 | — |
| microsoft Windows 8.1 | — |
| microsoft Windows RT 8.1 | — |
| microsoft Windows Server, version 1803 | — |
| microsoft Windows Server, version 1903 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H