ZeroHour

CVE-2022-37969

KEV ransomwaremass

Out-of-bounds write flaw in Microsoft Windows CLFS driver enables privilege escalation

CISA: Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
28%p98
Published
()
KEV added
AI analysis

The Windows Common Log File System (CLFS) driver contains an input-validation flaw (CWE-20) that leads to an out-of-bounds write (CWE-787), allowing an attacker who already has a foothold or local access on a system to escalate privileges. It is triggered when the driver processes malformed or specially crafted common log file data, rather than via a remote network request on its own. Successful exploitation yields elevated (typically SYSTEM-level) privileges, giving the attacker full control of the host and making the bug a common post-exploitation link in ransomware chains. CISA lists the affected product broadly as 'Microsoft Windows', so essentially all Windows installations current at the time of disclosure were in scope. The flaw is confirmed exploited in the wild: CISA added it to the KEV catalog on 2022-09-14 with known ransomware use, EPSS puts 30-day exploitation probability at 28.3% (98th percentile), and no public PoC is known.

What to do: Apply Microsoft's September 2022 (or later) cumulative updates to every Windows host per vendor instructions, prioritizing endpoints and servers exposed for user or remote access. Because this is a local privilege escalation, treat it as a post-exploitation risk: also harden and patch initial-access surfaces (RDP, VPN, other exposed services) and hunt for signs of compromise such as unexpected SYSTEM-spawned processes or anomalous activity involving clfs.sys. Ransomware operators are known to use this bug, so remediation should be treated as urgent.

Affected
Microsoft Windows
Estimated exposure
mass>1 billion Windows devices (essentially all Windows installations at the time of disclosure; exploitation requires an existing local foothold) — Windows is the dominant desktop and server OS with over a billion active devices, and the KEV entry covers the Windows product line broadly rather than a niche component.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 21h2, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news