PT-2025-21008 · Microsoft · Windows Common Log File System Driver+1
Benoit Sevens
·
Published
2025-05-13
·
Updated
2025-12-15
·
CVE-2025-32706
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Common Log File System Driver versions prior to the fixed version
Description
The issue is related to improper input validation in the Windows Common Log File System Driver, allowing an authorized attacker to elevate privileges locally. This vulnerability has been exploited in real-world attacks, with cases reported in companies in the USA, Venezuela, Spain, and Saudi Arabia. The estimated number of potentially affected devices is not specified.
Recommendations
To resolve the issue, update the Windows Common Log File System Driver to the latest version. As a temporary workaround, consider restricting access to the vulnerable driver until a patch is available. Additionally, ensure that all security updates from Microsoft are installed, as they may include patches for this vulnerability. If no specific fix is provided for a particular version, it is recommended to follow general best practices for securing Windows systems.
Exploit
Fix
LPE
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Common Log File System Driver