Microsoft Windows Common Log File System Driver是美国微软(Microsoft)公司的通用日志文件系统 (CLFS) API 提供了一个高性能、通用的日志文件子系统,专用客户端应用程序可以使用该子系统并且多个客户端可以共享以优化日志访问。 microsoft Windows Common Log File System Driver存在权限许可和访问控制问题漏洞。以下产品和版本受到影响:Windows 10 Version 1809 for 32-bit Sy
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Windows 10 Version 1507 | 10.0.10240.0< 10.0.10240.19060 |
affected |
| Microsoft | Windows 10 Version 1607 | 10.0.14393.0< 10.0.14393.4651 |
affected |
| Microsoft | Windows 10 Version 1809 | 10.0.17763.0< 10.0.17763.2183 |
affected |
10.0.0< 10.0.17763.2183 |
affected | ||
| Microsoft | Windows 10 Version 1909 | 10.0.0< 10.0.18363.1801 |
affected |
| Microsoft | Windows 10 Version 2004 | 10.0.0< 10.0.19041.1237 |
affected |
| Microsoft | Windows 10 Version 20H2 | 10.0.0< 10.0.19042.1237 |
affected |
| Microsoft | Windows 10 Version 21H1 | 10.0.0< 10.0.19043.1237 |
affected |
| Microsoft | Windows 7 | 6.1.0< 6.1.7601.25712 |
affected |
| Microsoft | Windows 7 Service Pack 1 | 6.1.0< 6.1.7601.25712 |
affected |
| Microsoft | Windows 8.1 | 6.3.0< 6.3.9600.20120 |
affected |
| Microsoft | Windows Server 2008 R2 Service Pack 1 | 6.1.7601.0< 6.1.7601.25712 |
affected |
| Microsoft | Windows Server 2008 R2 Service Pack 1 (Server Core installation) | 6.1.7601.0< 6.1.7601.25712 |
affected |
| Microsoft | Windows Server 2008 Service Pack 2 | 6.0.6003.0< 6.0.6003.21218 |
affected |
| Microsoft | Windows Server 2008 Service Pack 2 (Server Core installation) | 6.0.6003.0< 6.0.6003.21218 |
affected |
| Microsoft | Windows Server 2012 | 6.2.9200.0< 6.2.9200.23462 |
affected |
| Microsoft | Windows Server 2012 (Server Core installation) | 6.2.9200.0< 6.2.9200.23462 |
affected |
| Microsoft | Windows Server 2012 R2 | 6.3.9600.0< 6.3.9600.20120 |
affected |
| Microsoft | Windows Server 2012 R2 (Server Core installation) | 6.3.9600.0< 6.3.9600.20120 |
affected |
| Microsoft | Windows Server 2016 | 10.0.14393.0< 10.0.14393.4651 |
affected |
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.14393.0< 10.0.14393.4651 |
affected |
| Microsoft | Windows Server 2019 | 10.0.17763.0< 10.0.17763.2183 |
affected |
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.17763.0< 10.0.17763.2183 |
affected |
| Microsoft | Windows Server 2022 | 10.0.20348.0< 10.0.20348.230 |
affected |
| Microsoft | Windows Server version 2004 | 10.0.0< 10.0.19041.1237 |
affected |
| Microsoft | Windows Server version 20H2 | 10.0.0< 10.0.19042.1237 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2021-36955 | https://github.com/JiaJinRong12138/CVE-2021-36955-EXP | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-38647 | 9.8 CRITICAL | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
| CVE-2021-36954 | 8.8 HIGH | Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| CVE-2021-40444 | 8.8 HIGH | Microsoft MSHTML Remote Code Execution Vulnerability |
| CVE-2021-36965 | 8.8 HIGH | Windows WLAN AutoConfig Service Remote Code Execution Vulnerability |
| CVE-2021-26435 | 8.1 HIGH | Windows Scripting Engine Memory Corruption Vulnerability |
| CVE-2021-36967 | 8.0 HIGH | Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability |
| CVE-2021-38644 | 7.8 HIGH | Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability |
| CVE-2021-38626 | 7.8 HIGH | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2021-38648 | 7.8 HIGH | Open Management Infrastructure Elevation of Privilege Vulnerability |
| CVE-2021-38653 | 7.8 HIGH | Microsoft Office Visio Remote Code Execution Vulnerability |
| CVE-2021-38654 | 7.8 HIGH | Microsoft Office Visio Remote Code Execution Vulnerability |
| CVE-2021-38646 | 7.8 HIGH | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability |
| CVE-2021-38656 | 7.8 HIGH | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2021-38658 | 7.8 HIGH | Microsoft Office Graphics Remote Code Execution Vulnerability |
| CVE-2021-38659 | 7.8 HIGH | Microsoft Office Graphics Remote Code Execution Vulnerability |
| CVE-2021-38633 | 7.8 HIGH | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-38660 | 7.8 HIGH | Microsoft Office Graphics Remote Code Execution Vulnerability |
| CVE-2021-38630 | 7.8 HIGH | Windows Event Tracing Elevation of Privilege Vulnerability |
| CVE-2021-38628 | 7.8 HIGH | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2021-38655 | 7.8 HIGH | Microsoft Excel Remote Code Execution Vulnerability |
Showing top 20 of 61 CVEs. View all on vendor page → →
No comments yet