Impact
An attacker with local authenticated access to the Windows Common Log File System Driver can read sensitive information that should only be available to privileged code. This information leak can be leveraged to gain elevated privileges on the system. The weakness is classified as CWE-200, Information Exposure.
Affected Systems
The vulnerability impacts multiple Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, both standard and Server Core installations where applicable. Affected builds run on x86, x64, and arm64 architectures as documented by the CPE references.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity local privilege escalation. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authorized user who can trigger the driver to expose data, which the description indicates would then allow that user to elevate privileges. No specific public exploit is known, but the potential for local privilege escalation warrants rapid remediation.
OpenCVE Enrichment