← Back to exposed-win-zero-days

CVE-2024-49138

Windows CLFS Zero-Day

Overview

CVE-2024-49138 is a zero-day elevation of privilege vulnerability in the Windows Common Log File System (CLFS) kernel driver. It was patched by Microsoft in December 2024 and was notably exploited by ransomware operators.

Technical Details

Exploitation

CVE-2024-49138 was exploited in the wild by ransomware operators to escalate privileges on already compromised systems. The vulnerability allowed attackers to gain SYSTEM-level access, enabling them to disable security tools, deploy ransomware, and maintain persistence.

This was the last CLFS zero-day flaw exploited in the wild before the patch was released in December 2024. Elevation of privilege flaws in CLFS have been especially popular among ransomware operators due to their effectiveness in post-compromise scenarios.

Affected Systems

Patch Information

Microsoft released security updates for this vulnerability in December 2024. Users and administrators are strongly advised to apply the update immediately to prevent exploitation.

For systems that cannot be patched, Microsoft recommends monitoring for suspicious privilege escalation activity and restricting access to kernel-level functions.

Mitigation

References