CVE-2022-37969

Executive Summary

The CVE-2022-37969 flaw in the Windows Common Log File System (CLFS) driver allows attackers to gain elevated privileges by exploiting a race condition during file system operations. The vulnerability can be triggered remotely or locally, enabling execution of arbitrary code with SYSTEM rights. It is actively exploited in the wild, as flagged by CISA's KEV, posing a significant risk to enterprise Windows environments.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2022-09-13T19:15:12.323 - Last Modified: 2026-09-10T04:17:35.097

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2022-09-14)

Original Description: Windows Common Log File System Driver Elevation of Privilege Vulnerability

"Many of life's failures are people who did not realize how close they were to success when they gave up."

— Thomas Edison
Source: NVD