CVE-2025-29824
KEV ransomware PoC ×2massUse-After-Free Privilege Escalation in Microsoft Windows CLFS Driver (Actively Exploited)
CISA: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
CVE-2025-29824 is a use-after-free flaw (CWE-416) in the Windows Common Log File System (CLFS) kernel driver, scored 7.8 (High) with a local attack vector, low privileges required, and no user interaction. An authorized local attacker can trigger it by interacting with CLFS-managed log files in a way that references freed kernel memory. Successful exploitation elevates the attacker's local privileges, typically to SYSTEM, providing full control of the host that can be chained into ransomware deployment or lateral movement. Any unpatched system running the listed Windows 10, Windows 11, or Windows Server versions is affected. The flaw was exploited as a zero-day — reportedly by Play ransomware — before Microsoft shipped fixes in the April 2025 Patch Tuesday release; it was added to CISA's KEV catalog on 2025-04-08 with known ransomware use, and EPSS estimates a 13.9% probability of continued exploitation over 30 days (96th percentile).
What to do: Apply Microsoft's April 2025 Patch Tuesday security updates for your Windows version immediately — the vendor update is the only complete fix, and the flaw is on the KEV list with known ransomware use, so prioritize servers and endpoints used by privileged users. Until patched, limit untrusted local code execution and review hosts for post-exploitation privilege escalation; public detection and mitigation scripts (e.g., Vicarius) are available to help hunt for exploitation. Federal agencies must apply the vendor mitigations per BOD 22-01 deadlines or discontinue use of affected versions.
| microsoft Windows 10 1507 | 1507 |
| microsoft Windows 10 1607 | 1607 |
| microsoft Windows 10 1809 | 1809 |
| microsoft Windows 10 21H2 | 21H2 |
| microsoft Windows 10 22H2 | 22H2 |
| microsoft Windows 11 22H2 | 22H2 |
| microsoft Windows 11 23H2 | 23H2 |
| microsoft Windows 11 24H2 | 24H2 |
| microsoft Windows Server 2008 | 2008 |
| microsoft Windows Server 2012 | 2012 |
| microsoft Windows Server 2016 | 2016 |
| microsoft Windows Server 2019 | 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H