Important CVSS 7.8 EPSS 0.03229 🔬 Patch diffed 2021-09 archive

Executive Summary

None

Overview

7.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released Sep 14 2021
Last Updated Sep 14 2021
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.03229 — 0.86938 percentile
NVD CVSS 7.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Functional
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 7.2

EPSS Score

0.03229
probability of exploitation in the next 30 days
0.86938 percentile - updated 2026-07-25
View on FIRST.org

Affected Products

28 affected products
Product KB Article Severity Impact Restart Required
Windows 10 for 32-bit Systems 5005569 (Security Update) Important Elevation of Privilege Yes
Windows 10 for x64-based Systems 5005569 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for 32-bit Systems 5005573 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for x64-based Systems 5005573 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for 32-bit Systems 5005568 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for ARM64-based Systems 5005568 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5005568 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1909 for 32-bit Systems 5005566 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1909 for ARM64-based Systems 5005566 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1909 for x64-based Systems 5005566 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 2004 for 32-bit Systems 5005565 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 2004 for ARM64-based Systems 5005565 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 2004 for x64-based Systems 5005565 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 20H2 for 32-bit Systems 5005565 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 20H2 for ARM64-based Systems 5005565 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 20H2 for x64-based Systems 5005565 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H1 for 32-bit Systems 5005565 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H1 for ARM64-based Systems 5005565 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H1 for x64-based Systems 5005565 (Security Update) Important Elevation of Privilege Yes
Windows 7 for 32-bit Systems Service Pack 1 5005633 (Monthly Rollup) 5005615 (Security Only) Important Elevation of Privilege 5005088 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.25712 Yes 5005633 5005615 Windows 7 for x64-based Systems Service Pack 1 5005633 (Monthly Rollup) 5005615 (Security Only) Important Elevation of Privilege 5005088 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.25712 Yes 5005633 5005615 Windows 8.1 for 32-bit systems 5005613 (Monthly Rollup) 5005627 (Security Only) Important Elevation of Privilege 5005076 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.3.9600.20120 Yes 5005613 5005627 Windows 8.1 for x64-based systems 5005613 (Monthly Rollup) 5005627 (Security Only) Important Elevation of Privilege 5005076 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.3.9600.20120 Yes 5005613 5005627 Windows RT 8.1 5005613 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 5005606 (Monthly Rollup) 5005618 (Security Only) Important Elevation of Privilege 5005090 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.21218 Yes 5005606 5005618 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5005606 (Monthly Rollup) 5005618 (Security Only) Important Elevation of Privilege 5005090 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.21218 Yes 5005606 5005618 Windows Server 2008 for x64-based Systems Service Pack 2 5005606 (Monthly Rollup) 5005618 (Security Only) Important Elevation of Privilege 5005090 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.21218 Yes 5005606 5005618 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5005606 (Monthly Rollup) 5005618 (Security Only) Important Elevation of Privilege 5005090 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.21218 Yes 5005606 5005618 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5005633 (Monthly Rollup) 5005615 (Security Only) Important Elevation of Privilege 5005088 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.25712 Yes 5005633 5005615 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5005633 (Monthly Rollup) 5005615 (Security Only) Important Elevation of Privilege 5005088 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.25712 Yes 5005633 5005615 Windows Server 2012 5005623 (Monthly Rollup) 5005607 (Security Only) Important Elevation of Privilege 5005094 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.2.9200.23462 Yes 5005623 5005607 Windows Server 2012 (Server Core installation) 5005623 (Monthly Rollup) 5005607 (Security Only) Important Elevation of Privilege 5005094 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.2.9200.23462 Yes 5005623 5005607 Windows Server 2012 R2 5005613 (Monthly Rollup) 5005627 (Security Only) Important Elevation of Privilege 5005076 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.3.9600.20120 Yes 5005613 5005627 Windows Server 2012 R2 (Server Core installation) 5005613 (Monthly Rollup) 5005627 (Security Only) Important Elevation of Privilege 5005076 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.3.9600.20120 Yes 5005613 5005627 Windows Server 2016 5005573 (Security Update) Important Elevation of Privilege Yes
Windows Server 2016 (Server Core installation) 5005573 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5005568 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5005568 (Security Update) Important Elevation of Privilege Yes
Windows Server 2022 5005575 (Security Update) Important Elevation of Privilege Yes
Windows Server 2022 (Server Core installation) 5005575 (Security Update) Important Elevation of Privilege Yes
Windows Server, version 2004 (Server Core installation) 5005565 (Security Update) Important Elevation of Privilege Yes
Windows Server, version 20H2 (Server Core Installation) 5005565 (Security Update) Important Elevation of Privilege Yes

Patches

7 patches
Article Type Restart
5005569 Security Update Yes
5005573 Security Update Yes
5005568 Security Update Yes
5005566 Security Update Yes
5005565 Security Update Yes
5005613 Monthly Rollup Yes
5005575 Security Update Yes

Patch Diff

ghidriff · clfs.sys (KB5005565)

Patch diff 10.0.19041.1052 -> 10.0.19041.1237 (ITW clfs EoP; GetSymbol/container-create hardening)

Pre-patch version 10.0.19041.1052
Post-patch version 10.0.19041.1237
Function Address Change Note
__GSHandlerCheck 1c000cfb8 -> 1c000c288 refcount, address similarity 1.0
CClfsBaseFilePersisted::ExtendMetadataBlockDescriptor 1c004f3d8 -> 1c004e238 code, length, address, called similarity 0.12
CClfsLogFcbVirtual::Open 1c0044978 -> 1c00437e8 code, length, address, called similarity 0.99
CClfsBaseFilePersisted::CreateContainer 1c00299b4 -> 1c0028824 code, length, address, called similarity 0.78
_guard_dispatch_icall 1c000d1d0 -> 1c000c4a0 refcount, address, calling similarity 0.89
CClfsContainer::Create 1c0029d74 -> 1c0028bdc code, length, address, called similarity 0.85
CClfsBaseFile::GetSymbol 1c0031a68 -> 1c00308c8 code, length, address similarity 0.95
ClfsCreateLogFile 1c0032550 -> 1c00313d0 code, length, address, called similarity 0.66
NTOSKRNL.EXE::RtlQueryFeatureConfiguration EXTERNAL:00000004 refcount, calling similarity 1.0
CClfsBaseFile::GetSymbol 1c0032420 -> 1c0031290 code, length, address similarity 0.96
__security_check_cookie 1c000c190 -> 1c000c1b0 refcount, address, calling similarity 1.0
memset 1c000d4c0 -> 1c000c780 refcount, address, calling similarity 1.0
ClfsCreateLogFile$fin$0 1c0047c0a -> 1c0046a7a code, length, address, called similarity 0.83
NTOSKRNL.EXE::ExAllocatePoolWithTag EXTERNAL:00000001 refcount, calling similarity 1.0
NTOSKRNL.EXE::ExFreePoolWithTag EXTERNAL:00000002 refcount, calling similarity 1.0
View full diff report View RCA report Download PoC

Known Exploits

Acknowledgments

None