CVE-2024-49138

Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

7.8
CVSS 3.1
26.2 %
EPSS (current)
2024-12-10
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Microsoft / Windows

Published: 2024-12-12 · Due (CISA): 2024-12-31

CWE: CWE-122 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
exploitdb52270Microsoft Windows 11 23h2 - CLFS.sys Elevation of Privilege2025-04-22

References only — no downloads or instructions.

Sources