Microsoft Windows Common Log File System Driver是美国微软(Microsoft)公司的通用日志文件系统 (CLFS) API 提供了一个高性能、通用的日志文件子系统,专用客户端应用程序可以使用该子系统并且多个客户端可以共享以优化日志访问。 Microsoft Windows Common Log File System Driver存在资源管理错误漏洞。以下产品和版本受到影响:Windows 10 Version 1809 for 32-bit Systems
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/encrypter15/CVE-2025-29824 | POC Details |
| 2 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | https://github.com/AfanPan/CVE-2025-29824-Exploit | POC Details |
| 3 | note | https://github.com/zmkeh/CVE-2025-29824-CLFS-Local-privilege-escalation | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-21205 | 8.8 HIGH | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21221 | 8.8 HIGH | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-26669 | 8.8 HIGH | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
| CVE-2025-29794 | 8.8 HIGH | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2025-27477 | 8.8 HIGH | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-27740 | 8.8 HIGH | Active Directory Certificate Services Elevation of Privilege Vulnerability |
| CVE-2025-21222 | 8.8 HIGH | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-26647 | 8.8 HIGH | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2025-27481 | 8.8 HIGH | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-27737 | 8.6 HIGH | Windows Security Zone Mapping Security Feature Bypass Vulnerability |
| CVE-2025-26678 | 8.4 HIGH | Windows Defender Application Control Security Feature Bypass Vulnerability |
| CVE-2025-26663 | 8.1 HIGH | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
| CVE-2025-27482 | 8.1 HIGH | Windows Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2025-27480 | 8.1 HIGH | Windows Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2025-26670 | 8.1 HIGH | Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability |
| CVE-2025-26671 | 8.1 HIGH | Windows Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2025-27487 | 8.0 HIGH | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2025-24073 | 7.8 HIGH | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2025-26674 | 7.8 HIGH | Windows Media Remote Code Execution Vulnerability |
| CVE-2025-24062 | 7.8 HIGH | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
Showing top 20 of 119 CVEs. View all on vendor page → →
No comments yet