ZeroHour

CVE-2021-43226

KEV ransomwaremass1

Local Privilege Escalation in Microsoft Windows CLFS Driver (CVE-2021-43226)

CISA: Microsoft Windows Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p87
Published
()
KEV added
AI analysis

CVE-2021-43226 is an elevation-of-privilege vulnerability in the Windows Common Log File System (CLFS) driver, a kernel-mode component that manages common log files. A local attacker who already has limited privileges on a machine (the CVSS vector requires only low privileges, no user interaction, and a local attack vector) can trigger the flaw through crafted interactions with the CLFS driver and escalate to full SYSTEM-level control of the host. CISA notes known use in ransomware campaigns, where this class of local privilege escalation is typically chained after initial access. Affected deployments span essentially all supported Windows client releases of the era: Windows 7, Windows 8.1 and Windows RT 8.1, Windows 10 versions 1507 through 21H2, and Windows 11 21H2. The bug was patched in Microsoft's December 2021 Patch Tuesday as an actively exploited zero-day, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06 with ransomware use noted, indicating demonstrated in-the-wild exploitation.

What to do: Install the December 2021 Patch Tuesday (or any later) cumulative update for each affected release on all Windows 7, 8.1, Windows 10, and Windows 11 21H2 systems, and verify patch coverage through WSUS/Intune or equivalent inventory, per CISA KEV and BOD 22-01 guidance. Because this is a post-compromise privilege escalation used in ransomware chains, prioritize endpoints where low-privileged users can log in and hosts in ransomware-prone network segments.

Affected
microsoft Windows 101507, 1607, 1809, 1909, 2004, 20H2, 21H1, 21H2
microsoft Windows 1121H2
microsoft Windows 7
microsoft Windows 8.1
microsoft Windows RT 8.1
Estimated exposure
masshundreds of millions of Windows endpoints (Windows install base exceeds 1 billion devices) — Windows runs on more than 1 billion active devices, the vulnerable CLFS driver ships as a core component in every listed release, and substantial unpatched populations persist on Windows 7, 8.1 and Windows 10 builds, so hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 7, windows 8.1, windows rt 8.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news