Important CVSS 7.8 EPSS 0.28275 ⚠️ Exploited in the wild 📢 Publicly disclosed 🔬 Patch diffed 2022-09 archive

Executive Summary

None

Overview

7.8
CVSS HIGH
Important
MS Severity
Exploited
MS Exploit Status
Exploitation Detected
MS Exploit Likelihood
Category Elevation of Privilege
Released Sep 13 2022
Last Updated Sep 13 2022
Publicly Disclosed Yes
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.28275 — 0.97916 percentile
NVD CVSS 7.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.8

EPSS Score

0.28275
probability of exploitation in the next 30 days
0.97916 percentile - updated 2026-07-25
View on FIRST.org

Affected Products

22 affected products
Product KB Article Severity Impact Restart Required
Windows 10 for 32-bit Systems 5017327 (Security Update) Important Elevation of Privilege Yes
Windows 10 for x64-based Systems 5017327 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for 32-bit Systems 5017305 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for x64-based Systems 5017305 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for 32-bit Systems 5017315 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for ARM64-based Systems 5017315 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5017315 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 20H2 for 32-bit Systems 5017308 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 20H2 for ARM64-based Systems 5017308 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H1 for 32-bit Systems 5017308 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H1 for ARM64-based Systems 5017308 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H1 for x64-based Systems 5017308 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for 32-bit Systems 5017308 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5017308 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5017308 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 21H2 for ARM64-based Systems 5017328 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 21H2 for x64-based Systems 5017328 (Security Update) Important Elevation of Privilege Yes
Windows 7 for 32-bit Systems Service Pack 1 5017361 (Monthly Rollup) 5017373 (Security Only) Important Elevation of Privilege 5016676 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows 7 for x64-based Systems Service Pack 1 5017361 (Monthly Rollup) 5017373 (Security Only) Important Elevation of Privilege 5016676 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows 8.1 for 32-bit systems 5017367 (Monthly Rollup) 5017365 (Security Only) Important Elevation of Privilege 5016681 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows 8.1 for x64-based systems 5017367 (Monthly Rollup) 5017365 (Security Only) Important Elevation of Privilege 5016681 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows RT 8.1 5017367 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 5017358 (Monthly Rollup) 5017371 (Security Only) Important Elevation of Privilege 5016669 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5017358 (Monthly Rollup) 5017371 (Security Only) Important Elevation of Privilege 5016669 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 for x64-based Systems Service Pack 2 5017358 (Monthly Rollup) 5017371 (Security Only) Important Elevation of Privilege 5016669 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5017358 (Monthly Rollup) 5017371 (Security Only) Important Elevation of Privilege 5016669 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.21666 Yes 5017358 5017371 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5017361 (Monthly Rollup) 5017373 (Security Only) Important Elevation of Privilege 5016676 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5017361 (Monthly Rollup) 5017373 (Security Only) Important Elevation of Privilege 5016676 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.26115 Yes 5017361 5017373 Windows Server 2012 5017370 (Monthly Rollup) 5017377 (Security Only) Important Elevation of Privilege 5016672 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.23865 Yes 5017370 5017377 Windows Server 2012 (Server Core installation) 5017370 (Monthly Rollup) 5017377 (Security Only) Important Elevation of Privilege 5016672 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.2.9200.23865 Yes 5017370 5017377 Windows Server 2012 R2 5017367 (Monthly Rollup) 5017365 (Security Only) Important Elevation of Privilege 5016681 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows Server 2012 R2 (Server Core installation) 5017367 (Monthly Rollup) 5017365 (Security Only) Important Elevation of Privilege 5016681 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.3.9600.20571 Yes 5017367 5017365 Windows Server 2016 5017305 (Security Update) Important Elevation of Privilege Yes
Windows Server 2016 (Server Core installation) 5017305 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5017315 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5017315 (Security Update) Important Elevation of Privilege Yes

Patches

6 patches
Article Type Restart
5017327 Security Update Yes
5017305 Security Update Yes
5017315 Security Update Yes
5017308 Security Update Yes
5017328 Security Update Yes
5017367 Monthly Rollup Yes

Patch Diff

ghidriff · clfs.sys (KB5017328)

Patch diff 10.0.22000.832 -> 10.0.22000.978 (ITW clfs EoP; container-load symbol validation)

Pre-patch version 10.0.22000.832
Post-patch version 10.0.22000.978
Function Address Change Note
__GSHandlerCheck 1c000c9c8 -> 1c000d388 refcount, address similarity 1.0
_guard_dispatch_icall 1c000cc90 -> 1c000d650 refcount, address, calling similarity 0.89
CClfsBaseFile::OffsetToAddr 1c002cf40 -> 1c002eca0 refcount, address, calling similarity 1.0
CClfsRequest::DeleteContainer 1c0050b70 -> 1c0052c34 code, length, address, called similarity 0.4
CClfsBaseFile::GetSymbol 1c002cdd8 -> 1c002eb28 code, refcount, length, address, calling similarity 0.94
CClfsLogFcbPhysical::AcquireForReadAheadCallback 1c0002950 refcount similarity 1.0
NTOSKRNL.EXE::RtlQueryFeatureConfiguration EXTERNAL:00000007 refcount, calling similarity 1.0
NTOSKRNL.EXE::RtlInitializeGenericTableAvl EXTERNAL:00000075 -> EXTERNAL:00000023 refcount, address, calling similarity 1.0
`CClfsBaseFilePersisted::LoadContainerQ'::__l1::fin$0 1c0046d40 -> 1c0048da0 length, address similarity 0.88
RtlStringCbLengthW 1c001035c -> 1c00100a0 code, refcount, length, address, calling, called similarity 0.48
CClfsRequest::AllocContainer 1c0050740 -> 1c00527b0 code, length, address, called similarity 0.32
NTOSKRNL.EXE::RtlDeleteElementGenericTableAvl EXTERNAL:00000096 -> EXTERNAL:00000026 refcount, address, calling similarity 1.0
CClfsBaseFilePersisted::LoadContainerQ 1c0035ac0 -> 1c0037820 code, length, address, calling, called similarity 0.17
__security_check_cookie 1c000c7e0 refcount, calling similarity 1.0
NTOSKRNL.EXE::RtlLookupElementGenericTableAvl EXTERNAL:0000007f -> EXTERNAL:00000022 refcount, address, calling similarity 1.0
CClfsBaseFile::ContainerCount 1c002cecc -> 1c002ec2c refcount, address, calling similarity 1.0
NTOSKRNL.EXE::ExFreePoolWithTag EXTERNAL:00000002 refcount, calling similarity 1.0
NTOSKRNL.EXE::RtlInsertElementGenericTableAvl EXTERNAL:0000007b -> EXTERNAL:00000021 refcount, address, calling similarity 1.0
CClfsBaseFilePersisted::CreateImage 1c003a1f0 -> 1c003c270 code, length, address similarity 0.93
CClfsBaseFile::GetSymbol 1c002c2d0 -> 1c002e010 code, refcount, length, address, calling similarity 0.96
NTOSKRNL.EXE::RtlNumberGenericTableElementsAvl EXTERNAL:0000009f -> EXTERNAL:00000024 refcount, address, calling similarity 1.0
CClfsBaseFile::ClientCount 1c0041338 -> 1c0043398 refcount, address, calling similarity 1.0
NTOSKRNL.EXE::ExAllocatePoolWithTag EXTERNAL:00000001 refcount, calling similarity 1.0
CClfsBaseFile::freeOffsetNode 1c0059010 -> 1c0028200 name, fullname, refcount, sig, address, parent similarity 0.8
View full diff report View RCA report Download PoC

Known Exploits