ZeroHour

CVE-2021-36955

KEV ransomwaremass

Local Privilege Escalation in Microsoft Windows CLFS Driver

CISA: Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
4%p90
Published
()
KEV added
AI analysis

CVE-2021-36955 is an elevation-of-privilege vulnerability in the Windows Common Log File System (CLFS) driver, the kernel component responsible for managing log files used by various Windows features. An attacker who can already run code locally with limited user privileges can trigger the flaw in the CLFS driver and escalate to SYSTEM without any user interaction (CVSS 3.1: 7.8, local vector, low privileges required). Successful exploitation grants full SYSTEM-level control of the host, which adversaries use to disable security tooling and chain with other exploits during ransomware operations. The affected footprint is broad: Windows 7, 8.1, RT 8.1, Windows 10 builds 1507 through 21H1, and Windows Server 2004 and 2008 as listed in CISA's data. The flaw is confirmed exploited in the wild and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use; no standalone public proof-of-concept is known.

What to do: Apply the Microsoft Windows security updates that fix this flaw across all affected versions immediately, per the CISA KEV required action (the fix was shipped in Microsoft's monthly Patch Tuesday updates, including the September 2021 release). Prioritize hosts where untrusted users can log on locally or via RDP, since this is a local privilege escalation used to reach SYSTEM in ransomware chains. Verify remediation with vulnerability scans and confirm your assets are cleared against the CISA KEV catalog.

Affected
Microsoft Windows 101507, 1607, 1809, 1909, 2004, 20H2, 21H1
Microsoft Windows 7
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server 2004
Microsoft Windows Server 2008
Estimated exposure
masshundreds of millions of Windows client and server installations worldwide — Windows 10 and Windows 7 together account for the overwhelming majority of desktop operating systems in use, and the affected versions were broadly deployed on enterprise endpoints and servers when the flaw was disclosed, putting the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 7, windows 8.1, windows rt 8.1, windows server 2004, windows server 2008
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news