PT-2025-15596 · Microsoft · Windows
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 10 version 1507 prior to 10.0.10240.20978
Microsoft Windows 10 version 1607 prior to 10.0.14393.7969
Microsoft Windows 10 version 1809 prior to 10.0.17763.7136
Microsoft Windows 10 version 21H2 prior to 10.0.19044.5737
Microsoft Windows 10 version 22H2 prior to 10.0.19045.5737
Microsoft Windows 11 (affected versions not specified)
Microsoft Windows Server (affected versions not specified)
Description
A use-after-free flaw exists in the Windows Common Log File System (CLFS) driver, which is a kernel driver responsible for logging. This issue allows an authorized local attacker to elevate their privileges to the SYSTEM level. The flaw is caused by a race condition between the
IRP MJ CLEANUP and IRP MJ CLOSE handlers, leading to the use of the FsContext2 pointer after the object it references has been freed.Real-world exploitation has been observed by ransomware groups, including RansomEXX and the Storm-2460 actor using the PipeMagic modular backdoor. In these attacks, the
clfs.sys driver was abused to gain system privileges, often following the use of certutil and MSBuild to deliver payloads. Technical analysis indicates that attackers used the NtQuerySystemInformation function to obtain kernel addresses and the RtlSetAllBits function within the kernel to enable all process privileges by corrupting the EPROCESS structure. To interact with the driver, attackers created a specific file at C:ProgramDataSkyPdfPDUDrv.blf.Recommendations
Update Microsoft Windows 10 version 1507 to 10.0.10240.20978 or later.
Update Microsoft Windows 10 version 1607 to 10.0.14393.7969 or later.
Update Microsoft Windows 10 version 1809 to 10.0.17763.7136 or later.
Update Microsoft Windows 10 version 21H2 to 10.0.19044.5737 or later.
Update Microsoft Windows 10 version 22H2 to 10.0.19045.5737 or later.
Apply the April 2025 security updates (including KB5055523 and KB5055528) for Microsoft Windows 11.
Apply the April 2025 security updates for Microsoft Windows Server.
As a temporary mitigation, restrict access to the
clfs.sys driver to minimize the risk of local privilege escalation.Exploit
Fix
DoS
LPE
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows