CVE-2025-32706: Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Other sources
Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally.
— CISA
Windows Common Log File System Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.4061Fixed in 10.0.26100.3981Patch KB5058497 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.5335Patch KB5058405 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5854Patch KB5058379 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.5335Patch KB5058405 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22577Patch KB5058403 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5854Patch KB5058379 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25475Patch KB5058451 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27729Patch KB5058454 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23279Patch KB5058429 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8066Patch KB5058383 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.21014Patch KB5058387 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1611Patch KB5058384 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.3692Patch KB5058385 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.3692Fixed in 10.0.20348.3630Patch KB5058500 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.7314Patch KB5058392 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.10240.21014Patch KB5058387 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.14393.8066Patch KB5058383 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.17763.7314Patch KB5058392 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.19044.5854Patch KB5058379 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.19045.5854Patch KB5058379 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.20348.3692Patch KB5058385 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.20348.3692Patch KB5058500 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.20348.3630Patch KB5058500 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.22621.5335Patch KB5058405 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.22631.5335Patch KB5058405 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.25398.1611Patch KB5058384 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.26100.4061Patch KB5058497 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.26100.3981Patch KB5058497 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 6.0.6003.23279Patch KB5058429 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 6.1.7601.27729Patch KB5058454 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 6.2.9200.25475Patch KB5058451 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 6.3.9600.22577Patch KB5058403
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32706?
CVE-2025-32706 is classified as a high severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2025-32706?
To fix CVE-2025-32706, ensure that you apply the latest security updates provided by Microsoft for the affected Windows versions.
Which Windows versions are affected by CVE-2025-32706?
CVE-2025-32706 affects multiple versions of Windows including Windows 10, Windows 11, and various Windows Server editions.
Can CVE-2025-32706 be exploited remotely?
No, CVE-2025-32706 requires local access to the system for an attacker to exploit the vulnerability.
What type of vulnerability is CVE-2025-32706?
CVE-2025-32706 is an improper input validation vulnerability found in the Windows Common Log File System Driver.