CVE-2025-32701
KEVmassUse-After-Free Local Privilege Escalation in Microsoft Windows CLFS Driver
CISA: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
CVE-2025-32701 is a use-after-free (CWE-416) in the Windows Common Log File System (CLFS) driver, a kernel component that manages log files for Windows and third-party applications. An attacker who already has valid low-privileged access to a target machine can trigger the flaw through local operations against the CLFS driver, with no user interaction required. Successful exploitation allows elevation of privileges on the local system, with high impact on confidentiality, integrity, and availability (typically yielding SYSTEM-level rights). Any organization running the affected Windows 10/11 client releases or Windows Server 2008/2012/2016/2019 is in scope, which covers effectively the entire supported Windows installed base. Microsoft patched the flaw in the May 2025 Patch Tuesday release as one of five zero-days under active exploitation, and CISA added it to the Known Exploited Vulnerabilities catalog on May 13, 2025; no public proof-of-concept is known and ransomware use has not been confirmed.
What to do: Apply Microsoft's May 2025 Patch Tuesday security updates (released May 13, 2025) to every affected Windows 10/11 and Windows Server system and verify installation across the fleet, prioritizing multi-user servers, RDS hosts, and shared workstations where any local user or malware could leverage it for SYSTEM-level access. Because exploitation requires a local foothold, treat this bug as a prime chaining target for other exploits and malware; with no public PoC and no documented workaround in the data, patching is the only reliable mitigation, and defenders should hunt for anomalous CLFS driver activity on unpatched hosts.
| Microsoft Windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 22H2, 23H2, 24H2 |
| Microsoft Windows Server | 2008, 2012, 2016, 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H