CVE-2022-37969 — Windows Common Log File System Driver Elevation of Privilege Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5017327 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 for x64-based Systems | 5017327 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5017305 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5017305 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5017315 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 5017315 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5017315 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 20H2 for 32-bit Systems | 5017308 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 20H2 for ARM64-based Systems | 5017308 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H1 for 32-bit Systems | 5017308 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H1 for ARM64-based Systems | 5017308 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H1 for x64-based Systems | 5017308 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5017308 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5017308 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5017308 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for ARM64-based Systems | 5017328 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for x64-based Systems | 5017328 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 7 for 32-bit Systems Service Pack 1 5017361 (Monthly Rollup) 5017373 (Security Only) Important Elevation of Privilege 5016676 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows 7 for x64-based Systems Service Pack 1 5017361 (Monthly Rollup) 5017373 (Security Only) Important Elevation of Privilege 5016676 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows 8.1 for 32-bit systems 5017367 (Monthly Rollup) 5017365 (Security Only) Important Elevation of Privilege 5016681 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows 8.1 for x64-based systems 5017367 (Monthly Rollup) 5017365 (Security Only) Important Elevation of Privilege 5016681 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows RT 8.1 | 5017367 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 5017358 (Monthly Rollup) 5017371 (Security Only) Important Elevation of Privilege 5016669 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5017358 (Monthly Rollup) 5017371 (Security Only) Important Elevation of Privilege 5016669 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 for x64-based Systems Service Pack 2 5017358 (Monthly Rollup) 5017371 (Security Only) Important Elevation of Privilege 5016669 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5017358 (Monthly Rollup) 5017371 (Security Only) Important Elevation of Privilege 5016669 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5017361 (Monthly Rollup) 5017373 (Security Only) Important Elevation of Privilege 5016676 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5017361 (Monthly Rollup) 5017373 (Security Only) Important Elevation of Privilege 5016676 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows Server 2012 5017370 (Monthly Rollup) 5017377 (Security Only) Important Elevation of Privilege 5016672 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.23865 Yes 5017370 5017377 Windows Server 2012 (Server Core installation) 5017370 (Monthly Rollup) 5017377 (Security Only) Important Elevation of Privilege 5016672 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.23865 Yes 5017370 5017377 Windows Server 2012 R2 5017367 (Monthly Rollup) 5017365 (Security Only) Important Elevation of Privilege 5016681 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows Server 2012 R2 (Server Core installation) 5017367 (Monthly Rollup) 5017365 (Security Only) Important Elevation of Privilege 5016681 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows Server 2016 | 5017305 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5017305 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5017315 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5017315 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5017327 |
Security Update | Yes |
5017305 |
Security Update | Yes |
5017315 |
Security Update | Yes |
5017308 |
Security Update | Yes |
5017328 |
Security Update | Yes |
5017367 |
Monthly Rollup | Yes |
Patch Diff
Windows CLFS Driver Elevation of Privilege. Zero-day vulnerability in clfs.sys used in ITW exploitation. Patch adds validation in container allocation and reset paths.
| Function | Address | Change | Note |
|---|---|---|---|
CClfsBaseFilePersisted::AllocSymbol |
|
modified | From kb entry |
CClfsLogFcbPhysical::ResetLog |
|
modified | From kb entry |
CClfsBaseFilePersisted::LoadContainerQ |
|
modified | From kb entry |
Attack Path
Kernel pool pointer overwrite via a four-step signature-corruption chain that inflates SignaturesOffset past its bounds check
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
6 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| fortra/CVE-2022-37969 | 133 | 2023-03-09 | Windows LPE exploit for CVE-2022-37969 |
| NoobCat2000/CVE-2022-37969 | 2 | 2025-07-06 | |
| EmilC3978/CVE-2022-37969PoC | 2 | 2025-11-25 | Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes |
| grass341/CVE-2022-37969 | 1 | 2025-06-14 | |
| uname1able/CVE-2022-37969 | 0 | 2026-02-20 | CVE-2022-37969 poc |
| nhh9905/CVE-2022-37969 | 0 | 2026-05-15 |
Detection Rules
Acknowledgments
Zscaler ThreatLabz
CrowdStrike
Genwei Jiang with Mandiant, FLARE OTF
Quan Jin