LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-36955: Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-36955 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

CVE-2021-36955 is a privilege escalation vulnerability in the Microsoft Windows Common Log File System (CLFS) driver. An attacker who already has a foothold on a system can abuse it to gain higher privileges. CISA notes that this vulnerability has been used in ransomware activity, so organizations running Windows should treat it as a priority for inventory and remediation.

Public detail on the exact weakness class is limited; the CISA summary describes an unspecified flaw in the CLFS driver that enables privilege escalation. Confirm all version, patch, and configuration specifics against the Microsoft vendor advisory before acting.

How it works

The Common Log File System driver is a kernel-mode component that Windows uses for structured logging. Privilege-escalation flaws in kernel drivers typically let a local attacker with limited rights manipulate driver state or inputs so that code runs with SYSTEM or equivalent privileges. Once elevated, the attacker can disable defenses, move laterally, install persistence, or deploy ransomware.

Because the CWE is not specified in the available record, defenders should assume a classic local elevation path against the CLFS driver rather than inventing exploit mechanics. Successful abuse generally requires the attacker to already execute code in a user context on the target host; remote unauthenticated exploitation is not indicated by the given facts. Treat any confirmed exploitation as a full host compromise until proven otherwise.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the CLFS driver, which is present on standard Windows client and server installations. Inventory every Windows endpoint and server, including virtual machines, golden images, and infrequently patched systems such as jump hosts or industrial workstations.

Prioritize internet-facing jump boxes, RDP servers, and any host where untrusted users or malware can obtain an initial low-privilege foothold.

How to remediate

Apply the Microsoft updates that address CVE-2021-36955 exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions. After patching, reboot as required so the updated CLFS driver is loaded.

If you can't patch immediately

When immediate patching is impossible, reduce the attack surface and increase detection until the update can be applied.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently used after initial access to deploy ransomware or to steal data. If you have evidence of exploitation or of ransomware activity on affected hosts, follow your incident-response plan: isolate systems, preserve forensic images, rotate credentials, and assess what data the elevated attacker could have reached. You can also run a free exposure scan of your email addresses against known breach data to see whether associated credentials or personal information already appear in public breach corpora, then force password resets and enable phishing-resistant MFA where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities