CVE-2022-37969: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
Other sources
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21666Patch KB5017371 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20571Patch KB5017365 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23865Patch KB5017377 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26115Patch KB5017373 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20571Patch KB5017367 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5356Patch KB5017305 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19444Patch KB5017327 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2006Patch KB5017308 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.978Patch KB5017328 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2006Patch KB5017308 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1006Fixed in 10.0.20348.916Patch KB5017392 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.2006Patch KB5017308 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.3406Patch KB5017315
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37969?
CVE-2022-37969 is classified as a privilege escalation vulnerability in the Microsoft Windows Common Log File System driver.
How do I fix CVE-2022-37969?
To fix CVE-2022-37969, apply the relevant security updates provided by Microsoft for the affected Windows versions.
Which Windows versions are affected by CVE-2022-37969?
CVE-2022-37969 affects multiple versions of Windows including Windows Server 2016, 2019, Windows 10 (various builds), Windows 7, and Windows 8.1.
Can CVE-2022-37969 be exploited remotely?
CVE-2022-37969 requires local access to exploit, making it less likely to be exploited remotely.
What are the potential impacts of exploiting CVE-2022-37969?
Exploiting CVE-2022-37969 could allow an attacker to gain elevated privileges on the affected system.