CVE-2021-43226

Executive Summary

The CVE-2021-43226 vulnerability in the Windows Common Log File System (CLFS) driver allows attackers to gain elevated privileges by exploiting a race condition during file system operations. The flaw can be triggered remotely or locally, enabling execution of arbitrary code with SYSTEM rights. Microsoft has issued a patch; the vulnerability is actively exploited in the wild per CISA KEV, posing a high risk to unpatched Windows systems.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2021-12-15T15:15:09.737 - Last Modified: 2026-08-22T04:16:54.773

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2025-10-06)

Original Description: Windows Common Log File System Driver Elevation of Privilege Vulnerability

"True silence is the rest of the mind; it is to the spirit what sleep is to the body, nourishment and refreshment."

— William Penn
Source: NVD