CVE-2025-32701CISA KEV
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
- Product
- Windows
- Added to KEV
- 13 May 2025
- Federal remediation due
- 3 Jun 2025
- Known ransomware use
- Not reported