ZeroHour

CVE-2025-29824

KEV ransomware PoC ×2mass

Use-After-Free Privilege Escalation in Microsoft Windows CLFS Driver (Actively Exploited)

CISA: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
14%p96
Published
()
KEV added
AI analysis

CVE-2025-29824 is a use-after-free flaw (CWE-416) in the Windows Common Log File System (CLFS) kernel driver, scored 7.8 (High) with a local attack vector, low privileges required, and no user interaction. An authorized local attacker can trigger it by interacting with CLFS-managed log files in a way that references freed kernel memory. Successful exploitation elevates the attacker's local privileges, typically to SYSTEM, providing full control of the host that can be chained into ransomware deployment or lateral movement. Any unpatched system running the listed Windows 10, Windows 11, or Windows Server versions is affected. The flaw was exploited as a zero-day — reportedly by Play ransomware — before Microsoft shipped fixes in the April 2025 Patch Tuesday release; it was added to CISA's KEV catalog on 2025-04-08 with known ransomware use, and EPSS estimates a 13.9% probability of continued exploitation over 30 days (96th percentile).

What to do: Apply Microsoft's April 2025 Patch Tuesday security updates for your Windows version immediately — the vendor update is the only complete fix, and the flaw is on the KEV list with known ransomware use, so prioritize servers and endpoints used by privileged users. Until patched, limit untrusted local code execution and review hosts for post-exploitation privilege escalation; public detection and mitigation scripts (e.g., Vicarius) are available to help hunt for exploitation. Federal agencies must apply the vendor mitigations per BOD 22-01 deadlines or discontinue use of affected versions.

Affected
microsoft Windows 10 15071507
microsoft Windows 10 16071607
microsoft Windows 10 18091809
microsoft Windows 10 21H221H2
microsoft Windows 10 22H222H2
microsoft Windows 11 22H222H2
microsoft Windows 11 23H223H2
microsoft Windows 11 24H224H2
microsoft Windows Server 20082008
microsoft Windows Server 20122012
microsoft Windows Server 20162016
microsoft Windows Server 20192019
Estimated exposure
massHundreds of millions of Windows devices worldwide — effectively every unpatched system on the listed Windows 10/11/Server versions (local privilege escalation,… — Microsoft's Windows 10/11 install base exceeds one billion devices and the CLFS driver is present by default on all listed versions, so exposure is bounded only by patch-adoption rates rather than by internet-facing scans.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news