Important CVSS 7.8 EPSS 0.00284 🔬 Patch diffed 2026-07 archive

Executive Summary

Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Overview

7.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Exploitation Unlikely
MS Exploit Likelihood
Category Elevation of Privilege
Released Jul 14 2026
Last Updated Jul 14 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00284 — 0.20756 percentile
NVD CVSS 7.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.8

EPSS Score

0.00284
probability of exploitation in the next 30 days
0.20756 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

27 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1607 for 32-bit Systems 5099535 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for x64-based Systems 5099535 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for 32-bit Systems 5099538 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5099538 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for 32-bit Systems 5099539 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5099539 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5099539 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for 32-bit Systems 5099539 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for ARM64-based Systems 5099539 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for x64-based Systems 5099539 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for ARM64-based Systems 5101650 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for x64-based Systems 5101650 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 25H2 for ARM64-based Systems 5101650 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 25H2 for x64-based Systems 5101650 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 26H1 for ARM64-based Systems 5101649 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 26H1 for x64-based Systems 5095051 (Security Update) Important Elevation of Privilege Yes
Windows Server 2012 5099445 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 (Server Core installation) 5099445 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 5099444 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 (Server Core installation) 5099444 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2016 5099535 (Security Update) Important Elevation of Privilege Yes
Windows Server 2016 (Server Core installation) 5099535 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5099538 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5099538 (Security Update) Important Elevation of Privilege Yes
Windows Server 2022 5099540 (Security Update) Important Elevation of Privilege Yes
Windows Server 2025 5099536 (Security Update) Important Elevation of Privilege Yes
Windows Server 2025 (Server Core installation) 5099536 (Security Update) Important Elevation of Privilege Yes

Patches

10 patches
Article Type Restart
5099535 Security Update Yes
5099538 Security Update Yes
5099539 Security Update Yes
5101650 Security Update Yes
5101649 Security Update Yes
5095051 Security Update Yes
5099445 Monthly Rollup Yes
5099444 Monthly Rollup Yes
5099540 Security Update Yes
5099536 Security Update Yes

Patch Diff

ghidriff · clfs.sys (KB5101650)

Information-disclosure scrub in CClfsBaseFileSnapshot::CopyImage. The base-file log image copied to a caller buffer previously included a live per-container-context pointer field (container_context+0x18); the patch lifts that field out of every container context, copies the sanitized image, then restores it. Constructor zero-inits a 0x2000-byte save area at this+0xa0. All gated behind WIL CFR Feature_326875449. Closes a kernel-pointer / info leak (CWE-200) usable toward local EoP.

Pre-patch version 10.0.26100.8737 Download
Post-patch version 10.0.26100.8875 Download
Function Address Change Note
CClfsBaseFile::ReleaseContainerContext 140064710 -> 140064860 refcount, address, calling similarity 1.0
ClfsLsnBlockOffset 140006d10 -> 1400070e0 refcount, address, calling similarity 0.88
CClfsLogFcbPhysical::AppendLog 1400056a0 -> 140005e00 code, length, address, called similarity 0.12
CClfsLogFcbPhysical::ValidateContainerSize 140068860 -> 1400689b0 refcount, address, calling, called similarity 0.97
CClfsBaseFileSnapshot::CClfsBaseFileSnapshot 140038da4 code, length, called similarity 0.78
CClfsLogFcbPhysical::RawSectorAlign 140004500 refcount similarity 1.0
CClfsBaseFile::AcquireContainerContext 140064610 -> 140064760 refcount, address, calling similarity 1.0
`CClfsBaseFileSnapshot::CopyImage'::__l1::fin$0 14007e7d0 -> 14007e920 code, length, address, called similarity 0.42
ClfsLsnContainer 140007b50 -> 1400077c0 refcount, address, calling similarity 0.88
CClfsLogFcbPhysical::AddLsnOffset 140068d10 -> 140068e60 refcount, address, calling, called similarity 0.99
wil_details_IsEnabledFallback 140011374 -> 1400110e4 refcount, address, calling similarity 1.0
memset 140018e00 -> 140018c00 refcount, address, calling similarity 1.0
CClfsBaseFileSnapshot::CopyImage 140039668 -> 1400396a0 code, length, address, called similarity 0.28
CClfsLogFcbPhysical::RawSectorAlign 1400044a0 refcount, calling similarity 1.0
CClfsBaseFile::freeOffsetNode 14000d620 -> 140076450 name, fullname, refcount, sig, address similarity 0.8
CClfsBaseFileSnapshot::FreeMetadataBlock 140076300 -> 14000d390 name, fullname, refcount, sig, address, parent similarity 1.0
View full diff report View RCA report Download PoC

Attack Path

Kernel address disclosure via CClfsBaseFileSnapshot::CopyImage leaking a container-context pointer into the archive metadata

Attack path for CVE-2026-50697 Kernel address disclosure via CClfsBaseFileSnapshot::CopyImage leaking a container-context pointer into the archive metadata 01 — ENTRY Attacker creates a CLFS log and adds a container as a standard user CreateLogFile() then AddLogContainer(). CLFS is a core kernel component present everywhere; logs can be created in any user-writable directory. No elevation required. 02 — CONTROLLED INPUT Drives the archival path so a snapshot of the base file is taken PrepareLogArchive() builds a CClfsBaseFileSnapshot. The added container guarantees a container context exists with a non-null pointer at +0x18 - that pointer is the value that leaks. 03 — PATH ReadLogArchiveMetadata sends the archive-read IOCTL into the driver IOCTL 0x80076856 -> CClfsDriver::LogIoDispatch -> ClfsDispatchIoRequest -> CClfsRequest::Dispatch -> CClfsRequest::ReadArchiveMetadata -> CClfsLogCcb::ReadArchiveMetadata -> CClfsBaseFileSnapshot::CopyImage. 04 — MISSING CHECK CopyImage copies the raw in-memory image without scrubbing embedded kernel pointers The container context pointer at +0x18 is copied verbatim into the buffer returned to user mode. The patch zeroes the pointer fields in the copied image before it leaves the kernel. 05 — PRIMITIVE Kernel pointer disclosed to an unprivileged caller - KASLR defeat Information disclosure only. Pairs with a separate write primitive to reach EoP, which is exactly what the neighbouring clfs.sys bugs provide.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Known Exploits

Acknowledgments

sweetchip
dd484a5a34dd0f6d5330345ffe642dfc