CVE-2022-24521: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Other sources
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25924Patch KB5012649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21446Patch KB5012632 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20337Patch KB5012670 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20337Patch KB5012639 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5066Patch KB5012596 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23679Patch KB5012666 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19265Patch KB5012653 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.1645Patch KB5012599 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.613Patch KB5012592 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1645Patch KB5012599 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1645Patch KB5012599 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.643Patch KB5012604 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.2212Patch KB5012591 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2803Patch KB5012647
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24521?
CVE-2022-24521 has been rated as a critical vulnerability due to its potential to allow elevation of privilege.
How do I fix CVE-2022-24521?
To fix CVE-2022-24521, you should install the security updates provided by Microsoft on the affected Windows versions.
Which systems are affected by CVE-2022-24521?
CVE-2022-24521 affects multiple Windows versions, including Windows 10, Windows Server 2012 R2, and Windows 11 among others.
What details are available about CVE-2022-24521?
CVE-2022-24521 refers to a vulnerability in the Windows Common Log File System Driver that allows for elevation of privilege.
Is there a workaround for CVE-2022-24521?
There is no recommended workaround for CVE-2022-24521; the best practice is to apply the available patches.