
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62470 is a heap-based buffer overflow vulnerability in the Windows Common Log File System (CLFS) Driver that allows a low-privileged local attacker to escalate privileges to SYSTEM level without requiring user interaction. Disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2008 through Windows Server 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) in the Windows Common Log File System (CLFS) Driver, a kernel-mode component responsible for managing log files used by various Windows subsystems. An attacker with low-privileged local access can trigger the overflow by sending malformed input to the CLFS driver, corrupting heap memory in a way that enables privilege escalation. No user interaction is required, and the attack complexity is rated Low, meaning exploitation does not depend on race conditions or other difficult-to-control factors. The vulnerability is also associated with CAPEC-92 (Forced Integer Overflow), suggesting the root cause may involve integer arithmetic errors that lead to undersized buffer allocation (Microsoft MSRC).
Successful exploitation allows a low-privileged local attacker to escalate to SYSTEM-level privileges, resulting in complete compromise of confidentiality, integrity, and availability on the affected host. An attacker who gains SYSTEM privileges can execute arbitrary code, install malware, access all data on the system, disable security controls, and pivot to other systems on the network. The vulnerability affects a wide range of Windows deployments — from legacy Windows Server 2008 to the latest Windows 11 25H2 and Windows Server 2025 — significantly broadening the potential attack surface in enterprise environments (Microsoft MSRC).
clfs.sys-interacting applications.clfs.sys during failed exploitation attempts..blf, .clfs extensions); unexpected modifications to log files in %SystemRoot%\System32\ or application log directories.Microsoft released patches on December 9, 2025 as part of the December 2025 Patch Tuesday. Affected systems should be updated to the following minimum build versions or later: Windows 10 1607 → 10.0.14393.8688; Windows 10 1809/Server 2019 → 10.0.17763.8146; Windows 10 21H2 → 10.0.19044.6691; Windows 10 22H2 → 10.0.19045.6691; Windows 11 23H2 → 10.0.22631.6345; Windows 11 24H2/Server 2025 → 10.0.26100.7392; Windows 11 25H2 → 10.0.26200.7392; Windows Server 2022 → 10.0.20348.4467; Windows Server 2022 23H2 → 10.0.25398.2025. No official workaround is available; patching is the only remediation. As interim risk reduction, restrict local user account access and enforce the principle of least privilege to limit the pool of potential attackers (Microsoft MSRC).
The December 2025 Patch Tuesday was broadly covered by security media, with outlets including BleepingComputer, Krebs on Security, Cisco Talos, and Zero Day Initiative publishing roundup analyses. CVE-2025-62470 was noted as one of several privilege escalation vulnerabilities in the CLFS driver patched this cycle, a component with a well-documented history of exploitation. Qualys and Sophos highlighted the breadth of affected Windows versions as a key concern for enterprise patch prioritization (BleepingComputer, ZDI Blog, Talos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."