PT-2025-15596 · Microsoft · Windows

·

CVE-2025-29824

·

Published

2025-04-08

·

Updated

2026-09-09

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows 10 version 1507 prior to 10.0.10240.20978 Microsoft Windows 10 version 1607 prior to 10.0.14393.7969 Microsoft Windows 10 version 1809 prior to 10.0.17763.7136 Microsoft Windows 10 version 21H2 prior to 10.0.19044.5737 Microsoft Windows 10 version 22H2 prior to 10.0.19045.5737 Microsoft Windows 11 (affected versions not specified) Microsoft Windows Server (affected versions not specified)
Description A use-after-free flaw exists in the Windows Common Log File System (CLFS) driver, which is a kernel driver responsible for logging. This issue allows an authorized local attacker to elevate their privileges to the SYSTEM level. The flaw is caused by a race condition between the IRP MJ CLEANUP and IRP MJ CLOSE handlers, leading to the use of the FsContext2 pointer after the object it references has been freed.
Real-world exploitation has been observed by ransomware groups, including RansomEXX and the Storm-2460 actor using the PipeMagic modular backdoor. In these attacks, the clfs.sys driver was abused to gain system privileges, often following the use of certutil and MSBuild to deliver payloads. Technical analysis indicates that attackers used the NtQuerySystemInformation function to obtain kernel addresses and the RtlSetAllBits function within the kernel to enable all process privileges by corrupting the EPROCESS structure. To interact with the driver, attackers created a specific file at C:ProgramDataSkyPdfPDUDrv.blf.
Recommendations Update Microsoft Windows 10 version 1507 to 10.0.10240.20978 or later. Update Microsoft Windows 10 version 1607 to 10.0.14393.7969 or later. Update Microsoft Windows 10 version 1809 to 10.0.17763.7136 or later. Update Microsoft Windows 10 version 21H2 to 10.0.19044.5737 or later. Update Microsoft Windows 10 version 22H2 to 10.0.19045.5737 or later. Apply the April 2025 security updates (including KB5055523 and KB5055528) for Microsoft Windows 11. Apply the April 2025 security updates for Microsoft Windows Server. As a temporary mitigation, restrict access to the clfs.sys driver to minimize the risk of local privilege escalation.

Exploit

Fix

DoS

LPE

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03926
CVE-2025-29824

Affected Products

Windows