CVE-2025-32713 — Windows Common Log File System Driver Elevation of Privilege Vulnerability
Executive Summary
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5060998 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 for x64-based Systems | 5060998 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5061010 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5061010 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5060531 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5060531 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5060533 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5060533 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5060533 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5060533 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5060533 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5060533 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5060999 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5060999 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5060999 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5060999 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5060842 (Security Update) 5060841 (SecurityHotpatchUpdate) Important Elevation of Privilege 5058411 5058497 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.4349 10.0.26100.4270 Yes None Windows 11 Version 24H2 for x64-based Systems 5060842 (Security Update) 5060841 (SecurityHotpatchUpdate) Important Elevation of Privilege 5058411 5058497 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.4349 10.0.26100.4270 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 5061026 (Monthly Rollup) 5061072 (Security Only) Important Elevation of Privilege 5058449 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23351 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5061026 (Monthly Rollup) 5061072 (Security Only) Important Elevation of Privilege 5058449 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23351 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 5061026 (Monthly Rollup) 5061072 (Security Only) Important Elevation of Privilege 5058449 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23351 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5061026 (Monthly Rollup) 5061072 (Security Only) Important Elevation of Privilege 5058449 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23351 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 5061078 (Monthly Rollup) 5061036 (Security Only) Important Elevation of Privilege 5058430 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27769 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5061078 (Monthly Rollup) 5061036 (Security Only) Important Elevation of Privilege 5058430 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27769 Yes None Windows Server 2012 | 5061059 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 (Server Core installation) | 5061059 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5061018 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5061018 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5061010 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5061010 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5060531 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5060531 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 5060526 (Security Update) 5060525 (SecurityHotpatchUpdate) Important Elevation of Privilege 5058385 5058500 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3807 10.0.20348.3745 Yes None Windows Server 2022 (Server Core installation) 5060526 (Security Update) 5060525 (SecurityHotpatchUpdate) Important Elevation of Privilege 5058385 5058500 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3807 10.0.20348.3745 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) | 5060118 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5060998 |
Security Update | Yes |
5061010 |
Security Update | Yes |
5060531 |
Security Update | Yes |
5060533 |
Security Update | Yes |
5060999 |
Security Update | Yes |
5061059 |
Monthly Rollup | Yes |
5061018 |
Monthly Rollup | Yes |
5060118 |
Security Update | Yes |
Patch Diff
Missing validation of the log sector size in clfs.sys CClfsLogFcbPhysical::ReadLogBlock. The value is read from the log's device/container context at (this+0x2c8)+0x90 and used in the read-buffer sizing and alignment arithmetic. The patch adds an up-front check that it is non-zero, at most 0x1000, 512-aligned and an exact divisor of a page - admitting only 0x200/0x400/0x800/0x1000. Gated behind Feature_3984600376; the unchecked path still ships and runs when the flag is disabled. Note this is the first of three separate ReadLogBlock fixes (2025-06, 2026-05 Server Feature_748929339, 2026-08 Feature_344697147) - three distinct defects, not a variant chain.
| Function | Address | Change | Note |
|---|---|---|---|
CClfsLogFcbPhysical::ReadLogBlock |
|
code (sector-size validation added, gated on Feature_3984600376) | The patch adds an up-front sanity check on the sector size read from the log's device/container context (`*(uint *)(*(longlong *)(this + 0x2c8) + 0x90)`): it must satisfy `size - 1 < 0x1000`, `(size & 0x1ff) == 0` and `0x1000 % size == 0` - i.e. one of 0x200 / 0x400 / 0x800 / 0x1000. Pre-patch the value flowed into the read-buffer arithmetic unchecked. The rest of the function is register-allocation churn from the added block. |
Feature_3984600376__private_IsEnabledDeviceUsageNoInline / _IsEnabledFallback |
|
added -- CFR gate | Both paths ship in 10.0.26100.4343. |
Attack Path
Unvalidated sector size drives the read-buffer arithmetic in ReadLogBlock
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Known Exploits
Acknowledgments
Seunghoe Kim with S2W Inc.