ZeroHour

CVE-2025-32701

KEVmass

Use-After-Free Local Privilege Escalation in Microsoft Windows CLFS Driver

CISA: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
1%p70
Published
()
KEV added
AI analysis

CVE-2025-32701 is a use-after-free (CWE-416) in the Windows Common Log File System (CLFS) driver, a kernel component that manages log files for Windows and third-party applications. An attacker who already has valid low-privileged access to a target machine can trigger the flaw through local operations against the CLFS driver, with no user interaction required. Successful exploitation allows elevation of privileges on the local system, with high impact on confidentiality, integrity, and availability (typically yielding SYSTEM-level rights). Any organization running the affected Windows 10/11 client releases or Windows Server 2008/2012/2016/2019 is in scope, which covers effectively the entire supported Windows installed base. Microsoft patched the flaw in the May 2025 Patch Tuesday release as one of five zero-days under active exploitation, and CISA added it to the Known Exploited Vulnerabilities catalog on May 13, 2025; no public proof-of-concept is known and ransomware use has not been confirmed.

What to do: Apply Microsoft's May 2025 Patch Tuesday security updates (released May 13, 2025) to every affected Windows 10/11 and Windows Server system and verify installation across the fleet, prioritizing multi-user servers, RDS hosts, and shared workstations where any local user or malware could leverage it for SYSTEM-level access. Because exploitation requires a local foothold, treat this bug as a prime chaining target for other exploits and malware; with no public PoC and no documented workaround in the data, patching is the only reliable mitigation, and defenders should hunt for anomalous CLFS driver activity on unpatched hosts.

Affected
Microsoft Windows 101507, 1607, 1809, 21H2, 22H2
Microsoft Windows 1122H2, 23H2, 24H2
Microsoft Windows Server2008, 2012, 2016, 2019
Estimated exposure
mass>1 billion Windows installations (all listed supported Windows 10/11 client versions plus widely deployed Windows Server releases) — The listed versions span essentially the entire supported Windows desktop estate (Windows runs on well over a billion active devices worldwide) and broadly deployed Windows Server versions, so the patching scope is fleet-wide even though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news