CVE-2025-62470 — Windows Common Log File System Driver Elevation of Privilege Vulnerability
Executive Summary
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems | 5071543 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5071543 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5071544 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5071544 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5071546 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5071546 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5071546 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5071546 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5071546 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5071546 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5071417 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5071417 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5072033 (Security Update) 5072014 (Security Hotpatch Update) Important Elevation of Privilege 5068861 5068966 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.7462 10.0.26100.7392 Yes None Windows 11 Version 24H2 for x64-based Systems 5072033 (Security Update) 5072014 (Security Hotpatch Update) Important Elevation of Privilege 5068861 5068966 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.7462 10.0.26100.7392 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5072033 (Security Update) 5072014 (Security Hotpatch Update) Important Elevation of Privilege 5068861 5068966 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.7462 10.0.26200.7392 Yes None Windows 11 Version 25H2 for x64-based Systems 5072033 (Security Update) 5072014 (Security Hotpatch Update) Important Elevation of Privilege 5068861 5068966 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.7462 10.0.26200.7392 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 5071504 (Monthly Rollup) 5071507 (Security Only) Important Elevation of Privilege 5068906 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23666 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5071504 (Monthly Rollup) 5071507 (Security Only) Important Elevation of Privilege 5068906 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23666 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 5071504 (Monthly Rollup) 5071507 (Security Only) Important Elevation of Privilege 5068906 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23666 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5071504 (Monthly Rollup) 5071507 (Security Only) Important Elevation of Privilege 5068906 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23666 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 5071501 (Monthly Rollup) 5071506 (Security Only) Important Elevation of Privilege 5068904 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.28064 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5071501 (Monthly Rollup) 5071506 (Security Only) Important Elevation of Privilege 5068904 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.28064 Yes None Windows Server 2012 | 5071505 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 (Server Core installation) | 5071505 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5071503 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5071503 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5071543 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5071543 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5071544 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5071544 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 5071547 (Security Update) 5071413 (Security Hotpatch Update) Important Elevation of Privilege 5068787 5068840 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.4529 10.0.20348.4467 Yes None Windows Server 2022 (Server Core installation) 5071547 (Security Update) 5071413 (Security Hotpatch Update) Important Elevation of Privilege 5068787 5068840 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.4529 10.0.20348.4467 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) | 5071542 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5071543 |
Security Update | Yes |
5071544 |
Security Update | Yes |
5071546 |
Security Update | Yes |
5071417 |
Security Update | Yes |
5071505 |
Monthly Rollup | Yes |
5071503 |
Monthly Rollup | Yes |
5071542 |
Security Update | Yes |
Patch Diff
Reservation-accounting hardening on the CLFS log client-context block (CCB+0x68, ReservedLogSpace). Pre-patch WriteRestart guarded the reservation only against ADD overflow (`ReservedLogSpace + userValue < 0`); ReserveAndAppendLog set an error inline on failure. The December patch, gated behind Feature_1757897016, adds a SUBTRACTION-underflow guard (`ReservedLogSpace - amount < 0`) alongside the existing add check, and routes the reservation-accounting failures through CClfsLogFcbCommon::ReportFlushFailure(8, -0x3fffffff) instead of silently setting STATUS_INSUFFICIENT_RESOURCES. WriteRestart additionally inlines the CClfsLogCcb::MarkAccessed StateFlags update (CCB+0x1c |= 8, LOCK/UNLOCK) and splits status tracking into two accumulators. This is the same +0x68 counter released by CClfsLogCcb::Cleanup in CVE-2025-29824 and incremented by WriteRestart in CVE-2025-24059 - the third patch in a 2025 sequence hardening one reservation field. Both branches ship in 10.0.26100.7462; the unguarded path runs when the flag is off. Verified by headless-Ghidra decompilation of both builds.
| Function | Address | Change | Note |
|---|---|---|---|
CClfsRequest::WriteRestart |
|
code (2nd status accumulator + inline MarkAccessed, gated Feature_1757897016) | 5295 -> 5932 chars. Adds Feature_1757897016 gate; splits the single status var into uVar7/local_78; replaces the CClfsLogCcb::MarkAccessed() call with an inline `if ((ccb->StateFlags(+0x1c) & 8)==0){LOCK; |= 8; UNLOCK}`. The +0x68 add-overflow guard (0xc01a0010) is retained. |
CClfsRequest::ReserveAndAppendLog |
|
code (subtraction-underflow guard added, gated Feature_1757897016) | 12665 -> 11716 chars. PRE guarded only `local_118 + ccb->ReservedLogSpace(+0x68) < 0`. POST guards BOTH `local_128 + ccb->ReservedLogSpace < 0` AND `ccb->ReservedLogSpace - local_118 < 0` - i.e. adds the subtraction-underflow case. Two inline LOCK/UNLOCK error stubs are replaced by CClfsLogFcbCommon::ReportFlushFailure(8, -0x3fffffff). New early-out `if (local_140==0 && local_128==0) goto done` under the flag. |
CClfsLogCcb::MarkAccessed |
14001536c |
NOT changed | Byte-identical pre/post (277 chars). ghidriff listed it on address/refcount grounds only. The March->December MarkAccessed hypothesis is ruled out: December inlines the accessed-bit set into WriteRestart rather than modifying the helper. |
CClfsLogFcbCommon::ReportFlushFailure |
|
NOT changed (new call target) | Byte-identical pre/post (673 chars). It is newly CALLED from ReserveAndAppendLog's failure paths, which is why ghidriff flagged it. |
Feature_1757897016__private_IsEnabledDeviceUsageNoInline / _IsEnabledFallback |
|
added -- CFR gate | Both paths ship in 10.0.26100.7462. |
Attack Path
The log-space reservation counter is guarded against overflow on addition but not underflow on subtraction, so reserved space can be driven negative
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Known Exploits
Acknowledgments
haowei yan(jingdong dawnslab)
0rb1t