CVE-2024-38196 — Windows Common Log File System Driver Elevation of Privilege Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5041782 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 for x64-based Systems | 5041782 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5041773 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5041773 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5041578 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5041578 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5041580 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for ARM64-based Systems | 5041592 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for x64-based Systems | 5041592 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5041585 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5041585 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5041585 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5041585 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems | 5041571 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for x64-based Systems | 5041571 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 5041850 (Monthly Rollup) 5041847 (Security Only) Important Elevation of Privilege 5040499 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22825 Yes 5041850 5041847 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5041850 (Monthly Rollup) 5041847 (Security Only) Important Elevation of Privilege 5040499 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22825 Yes 5041850 5041847 Windows Server 2008 for x64-based Systems Service Pack 2 5041850 (Monthly Rollup) 5041847 (Security Only) Important Elevation of Privilege 5040499 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22825 Yes 5041850 5041847 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5041850 (Monthly Rollup) 5041847 (Security Only) Important Elevation of Privilege 5040499 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.22825 Yes 5041850 5041847 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5041838 (Monthly Rollup) 5041823 (Security Only) Important Elevation of Privilege 5040497 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27277 Yes 5041838 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5041838 (Monthly Rollup) 5041823 (Security Only) Important Elevation of Privilege 5040497 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27277 Yes 5041838 Windows Server 2012 | 5041851 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 (Server Core installation) | 5041851 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5041828 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5041828 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5041773 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5041773 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5041578 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5041578 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 | 5041160 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 (Server Core installation) | 5041160 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022, 23H2 Edition (Server Core installation) | 5041573 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5041782 |
Security Update | Yes |
5041773 |
Security Update | Yes |
5041578 |
Security Update | Yes |
5041580 |
Security Update | Yes |
5041592 |
Security Update | Yes |
5041585 |
Security Update | Yes |
5041571 |
Security Update | Yes |
5041851 |
Monthly Rollup | Yes |
5041828 |
Monthly Rollup | Yes |
5041160 |
Security Update | Yes |
5041573 |
Security Update | Yes |
Patch Diff
Improper input validation (CWE-20) in the Windows Common Log File System driver clfs.sys base-log-file (.blf) metadata parsing, local EoP to SYSTEM. CLFS parses a base log file's control record, client contexts, container contexts and symbol tables - a structure full of self-referential offsets. PRE: the offset/length fields in the base-file metadata were not fully validated, so a crafted .blf could point offsets outside the valid region (symbol zone) and drive out-of-bounds access when CLFS resolves them (OffsetToAddr / GetSymbol / GetControlRecord). Diff of clfs.sys 10.0.26100.1301 -> .1455 (Aug 13 2024, KB5041571) confirms the fix: gated behind CFR flags Feature_110180665 / Feature_1868496191 / Feature_2458037564, CLFS adds/strengthens offset validation across the base-file parsers - ValidateOffsets, ValidateRgOffsets, ValidateClientContextOffsets, ValidateContainerContextOffsets and ValidateProcessQNode now bound each offset within the symbol zone (ValidateCheckifWithinSymbolZone) and cross-check the symbol length markers before OffsetToAddr resolves them, so a malformed .blf is rejected rather than parsed out of bounds.
| Function | Address | Change | Note |
|---|---|---|---|
CClfsBaseFile::ValidateClientContextOffsets |
code change |
code (client-context offsets validated against symbol zone) | Post: walks each client-context offset (param_2+idx*4+0x138), requires it in-range via ValidateCheckifWithinSymbolZone, resolves with OffsetToAddr, and cross-checks the symbol length fields (*(pv-0xc)/*(pv-0x10)) before use. |
CClfsBaseFile::ValidateContainerContextOffsets / ValidateOffsets / ValidateRgOffsets / ValidateProcessQNode |
code change |
code (offset validation strengthened) | The container-context, region and process-QNode offset validators are hardened with the same in-symbol-zone bounds checks. |
CClfsBaseFile::OffsetToAddr / GetSymbol / GetControlRecord / CClfsBaseFilePersisted::OpenImage/CreateImage |
code change |
code (base-file open/resolve paths updated) | Offset-resolution and base-file open/create paths updated to use the validated offsets. |
Feature_110180665 / Feature_1868496191 / Feature_2458037564 |
gate |
added (CFR gate) | CFR flags gating the strengthened .blf offset validation; the original under-validating parser still ships when disabled. |
Attack Path
A crafted CLFS base log file (.blf) supplies offsets outside the valid region, driving out-of-bounds access on parse
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
Detection Rules
Acknowledgments
luckyu with MatrixCup
Anonymous