CVE-2025-29824: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Other sources
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
— Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22523Patch KB5055557 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25423Patch KB5055581 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23220Patch KB5055596 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27670Patch KB5055570 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7969Patch KB5055521 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20978Patch KB5055547 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.3775Patch KB5055523 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1551Patch KB5055527 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.5189Patch KB5055528 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5737Patch KB5055518 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.5189Patch KB5055528 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5737Patch KB5055518 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.3453Patch KB5055526 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.7136Patch KB5055519 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.10240.20978Patch KB5055547 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.14393.7969Patch KB5055521 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.17763.7136Patch KB5055519 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.19044.5737Patch KB5055518 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.19045.5737Patch KB5055518 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.20348.3453Patch KB5055526 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.22621.5189Patch KB5055528 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.22631.5189Patch KB5055528 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.25398.1551Patch KB5055527 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.26100.3775Patch KB5055523 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 6.0.6003.23220Patch KB5055596 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 6.1.7601.27670Patch KB5055570 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 6.2.9200.25423Patch KB5055581 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 6.3.9600.22523Patch KB5055557 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29824?
CVE-2025-29824 is classified as a critical vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-29824?
To remediate CVE-2025-29824, users should apply the latest security patches provided by Microsoft for their specific Windows version.
Which Windows versions are affected by CVE-2025-29824?
CVE-2025-29824 affects various versions of Windows including Windows Server 2008, Windows 10, and Windows 11.
Can CVE-2025-29824 be exploited remotely?
No, CVE-2025-29824 requires local access for exploitation, limiting its threat to users with physical or authenticated access.
What are the risks of CVE-2025-29824 if left unpatched?
If left unpatched, CVE-2025-29824 can allow an authorized attacker to gain elevated privileges, potentially compromising system security.