CVE-2025-29824 is a use-after-free vulnerability in the Windows Common Log File System Driver that allows local privilege escalation. Despite being listed in CISA KEV indicating active exploitation, this is a local vulnerability that requires existing access to a Windows system and cannot be directly exploited over the internet.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2025-04-08
Added to CISA KEV: 2025-04-08 0 DAY BETWEEN CVE AND KEV
CVE-2025-29824 is a high-severity use-after-free (UAF) vulnerability in the Microsoft Windows Common Log File System (CLFS) driver that allows an authorized attacker to escalate privileges to `SYSTEM` level?id=CVE-2025-29824?kagi_q=CVE-2025-29824 [1].
CVE-2025-29824 is a high-severity (CVSS 7.8) elevation of privilege vulnerability exploited in the wild by the Storm-2460 threat actor via PipeMagic malware. A race condition in the CLFS driver’s handling of W32PROCESS structures, triggered via WaitForInputIdle, causes a UAF, allowing kernel memory…
Threat actors with links to Play ransomware family used a privilege escalation flaw in Windows CLFS driver to breach a U.S. organization. The attack involved a bespoke information stealer and a public-facing Cisco ASA as an entry point.
Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have discovered post-compromise exploitation of a ... Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have discovered post-compromise exploitation of a newly discover…
MSFT has some fairly (read: very) broad hunting rules on their site looking for post-exploitation behavior of CLFS exploitation and rasomware execution.