PT-2024-3710 · Microsoft · Windows Common Log File System Driver+1

Ingyu Tae

+2

·

Published

2024-05-14

·

Updated

2025-01-08

·

CVE-2024-30037

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Windows Common Log File System Driver (affected versions not specified)
Description: The issue is related to an elevation-of-privilege vulnerability in the Windows Common Log File System Driver. It is caused by an integer underflow, allowing attackers to execute low-privileged code on the target system and then exploit this vulnerability for local privilege escalation. The vulnerability can be exploited by attackers to affect the system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2024-04056
CVE-2024-30037
ZDI-24-495

Affected Products

Windows
Windows Common Log File System Driver