CVE-2021-43226 is a local privilege escalation vulnerability in the Windows Common Log File System (CLFS) driver that requires local access and low-level privileges to exploit. While it affects both client and server Windows systems, it cannot be exploited directly over the internet as it requires local system access.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2021-12-15
Added to CISA KEV: 2025-10-06 1391 DAYS BETWEEN CVE AND KEV
CVE-2021-43226 is a privilege escalation vulnerability residing in the Microsoft Windows Common Log File System (CLFS) driver [1]. It gained significant attention in October 2025 when it was added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog due to active exploitation in the wild [1] [5].
The CVE-2021-43226 vulnerability resides within Microsoft’s Common Log File System Driver, a core Windows component responsible for managing transaction logging operations. Microsoft Windows Privilege Escalation Flaw (CVE-2021-43226). This privilege escalation flaw allows local, authenticated attack…
The flaw affects multiple Windows versions, including Windows 10, 11, and Server editions. Recently added to CISA's Known Exploited ... Vulnerability Details.The flaw affects multiple Windows versions, including Windows 10, 11, and Server editions. Recently added to CISA’s Known Exploited Vulnerabil…
This CVE is in CISA's Known Exploited Vulnerabilities Catalog. Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and ... Official websites use .gov A .gov website belongs to an official government organization in the United States. ... CVE-2021-43226 Detail.
Active Exploitation and Impact While the specific threat actors exploiting CVE-2021-43226 have not been publicly identified, CISA’s sudden addition of this issue to its Known Exploited Vulnerabilities catalog on October 6, 2025, underscores the heightened risk.
CISA added CVE-2021-43226, a privilege escalation vulnerability in the Microsoft Windows Common Log File System (CLFS) Driver, to its Known Exploited Vulnerabilities catalog on October 6, 2025. This flaw allows local authenticated attackers to elevate privileges to SYSTEM level through buffer overfl…