CVE-2022-24521 — Windows Common Log File System Driver Elevation of Privilege Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5012653 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 for x64-based Systems | 5012653 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5012596 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5012596 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5012647 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 5012647 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5012647 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1909 for 32-bit Systems | 5012591 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1909 for ARM64-based Systems | 5012591 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1909 for x64-based Systems | 5012591 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 20H2 for 32-bit Systems | 5012599 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 20H2 for ARM64-based Systems | 5012599 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H1 for 32-bit Systems | 5012599 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H1 for ARM64-based Systems | 5012599 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H1 for x64-based Systems | 5012599 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5012599 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5012599 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5012599 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for ARM64-based Systems | 5012592 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for x64-based Systems | 5012592 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 7 for 32-bit Systems Service Pack 1 5012626 (Monthly Rollup) 5012649 (Security Only) Important Elevation of Privilege 5011552 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.25924 Yes 5012626 5012649 Windows 7 for x64-based Systems Service Pack 1 5012626 (Monthly Rollup) 5012649 (Security Only) Important Elevation of Privilege 5011552 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.25924 Yes 5012626 5012649 Windows 8.1 for 32-bit systems 5012670 (Monthly Rollup) 5012639 (Security Only) Important Elevation of Privilege 5011564 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.3.9600.20337 Yes 5012670 5012639 Windows 8.1 for x64-based systems 5012670 (Monthly Rollup) 5012639 (Security Only) Important Elevation of Privilege 5011564 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.3.9600.20337 Yes 5012670 5012639 Windows RT 8.1 | 5012670 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 5012658 (Monthly Rollup) 5012632 (Security Only) Important Elevation of Privilege 5011534 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.21446 Yes 5012658 5012632 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5012658 (Monthly Rollup) 5012632 (Security Only) Important Elevation of Privilege 5011534 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.21446 Yes 5012658 5012632 Windows Server 2008 for x64-based Systems Service Pack 2 5012658 (Monthly Rollup) 5012632 (Security Only) Important Elevation of Privilege 5011534 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.21446 Yes 5012658 5012632 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5012658 (Monthly Rollup) 5012632 (Security Only) Important Elevation of Privilege 5011534 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.21446 Yes 5012658 5012632 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5012626 (Monthly Rollup) 5012649 (Security Only) Important Elevation of Privilege 5011552 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.25924 Yes 5012626 5012649 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5012626 (Monthly Rollup) 5012649 (Security Only) Important Elevation of Privilege 5011552 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.25924 Yes 5012626 5012649 Windows Server 2012 5012650 (Monthly Rollup) 5012666 (Security Only) Important Elevation of Privilege 5011535 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.2.9200.23679 Yes 5012650 5012666 Windows Server 2012 (Server Core installation) 5012650 (Monthly Rollup) 5012666 (Security Only) Important Elevation of Privilege 5011535 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.2.9200.23679 Yes 5012650 5012666 Windows Server 2012 R2 5012670 (Monthly Rollup) 5012639 (Security Only) Important Elevation of Privilege 5011564 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.3.9600.20337 Yes 5012670 5012639 Windows Server 2012 R2 (Server Core installation) 5012670 (Monthly Rollup) 5012639 (Security Only) Important Elevation of Privilege 5011564 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.3.9600.20337 Yes 5012670 5012639 Windows Server 2016 | 5012596 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5012596 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5012647 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5012647 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 | 5012604 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 (Server Core installation) | 5012604 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server, version 20H2 (Server Core Installation) | 5012599 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5012653 |
Security Update | Yes |
5012596 |
Security Update | Yes |
5012647 |
Security Update | Yes |
5012591 |
Security Update | Yes |
5012599 |
Security Update | Yes |
5012592 |
Security Update | Yes |
5012670 |
Monthly Rollup | Yes |
5012604 |
Security Update | Yes |
Patch Diff
Logical-error EoP (ITW 0-day): _CLFS_CONTAINER_CONTEXT->pContainer lives in the base log record and is round-tripped through ClfsEncodeBlock/ClfsDecodeBlock. A crafted .blf overlapping the signatures array (SignaturesOffset) with a container context lets encode/decode resurrect attacker bytes over the kernel-zeroed pContainer; RemoveContainer then performs two indirect calls through it -> kernel RIP control. Patch adds CClfsBaseFile::ValidateRgOffsets (new) called from LoadContainerQ behind Feature_Servicing_38197809: sorts record object offsets (qsort/CompareOffsets), validates CLFS_NODE_IDs, and rejects any record whose context objects cross SignaturesOffset (STATUS_LOG_METADATA_INVALID 0xC01A000D). Secondary hardening: CClfsLogFcbVirtual::Open now KeBugCheckEx-es on internal inconsistency. 2,836/2,838 functions matched; 2 added, 8 code-changed.
| Function | Address | Change | Note |
|---|---|---|---|
CClfsBaseFile::ValidateRgOffsets |
1c00274bc |
added (new function) | 267 bytes; calls OffsetToAddr + qsort; called only from LoadContainerQ; the CVE-2022-24521 fix |
Feature_Servicing_38197809__private_IsEnabled |
1c000c8d4 |
added (new function) | 94 bytes; WIL CFR flag gating the new validation block |
CClfsBaseFilePersisted::LoadContainerQ |
1c0036a90 -> 1c0036ba0 |
code, length, address, calling, called | 2927 -> 3160 bytes, b_ratio 0.85; new flag-gated ValidateRgOffsets call; now calls ValidateRgOffsets + Feature_Servicing_38197809__private_IsEnabled |
CClfsLogFcbVirtual::Open |
1c0042b40 -> 1c0042d40 |
code, length, address, called | 974 -> 1046 bytes, ratio 0.99; new KeBugCheckEx call (secondary hardening) |
`CClfsBaseFilePersisted::LoadContainerQ'::__l1::fin$0 |
|
code, length, address, called | ratio 0.98; SEH funclet updated to clean up new 0x11f0 scratch buffer |
Feature_Servicing_37529451__private_IsEnabled |
|
code | ratio 0.91; pre-existing WIL flag accessor, recompiled (state-cache layout shift) |
wil_details_FeatureReporting_RecordUsageInCache |
|
code | ratio 0.97; WIL telemetry plumbing for new flag |
wil_details_FeatureReporting_ReportUsageToServiceDirect |
|
code | ratio 0.90; WIL telemetry plumbing |
wil_details_FeatureReporting_IncrementUsageInCache |
|
code | ratio 0.98; WIL telemetry plumbing |
wil_details_FeatureReporting_ReportUsageToService |
|
code | ratio 0.87; WIL telemetry plumbing |
OffsetToAddr |
|
calling (no code changes) | referenced by new ValidateRgOffsets |
CompareOffsets |
|
no code changes | qsort comparator used by new ValidateRgOffsets |
NTOSKRNL.EXE::qsort |
|
calling (no code changes) | referenced by new ValidateRgOffsets |
operator_new / operator_delete |
|
no code changes | scratch-buffer alloc/free in patched LoadContainerQ |
Known Exploits
Acknowledgments
Adam Podlosky and Amir Bazine of Crowdstrike
National Security Agency