Home🪟 Windows SecurityCVE-2025-29824: CLFS Driver Zero-Day Exp...
🪟 Windows Security CRITICAL

CVE-2025-29824: CLFS Driver Zero-Day Exploited by RansomEXX

👤 admin 📅 May 15, 2025 👁 9 views
A use-after-free in the Windows Common Log File System (CLFS) driver was exploited as a zero-day by the RansomEXX ransomware group before Microsoft patched it in April 2025.

Overview

CVE-2025-29824 is a use-after-free vulnerability in the Windows Common Log File System (CLFS) kernel driver (clfs.sys). Microsoft confirmed active exploitation by the RansomEXX ransomware group (tracked as Storm-2460) prior to the April 2025 Patch Tuesday fix.

Affected Versions

  • Windows 10 (all supported versions)
  • Windows 11 22H2, 23H2 — Note: 24H2 was NOT affected
  • Windows Server 2016, 2019, 2022

Exploitation in the Wild

Attackers used this vulnerability as a post-exploitation privilege escalation step following initial access via phishing. The exploit allowed unprivileged users to corrupt kernel memory and inject code into SYSTEM-level processes before deploying the ransomware payload.

Patch

Fixed in KB5055523 / KB5055521 (April 8, 2025 Patch Tuesday). Apply immediately. If immediate patching is not possible, restrict clfs.sys access via ASR rules and enable Microsoft Defender for Endpoint behavioral blocking.

CVE-2025-29824 CLFS Zero-Day Ransomware RansomEXX Storm-2460
← Back to 🪟 Windows Security 🛡️ Request Assessment
⚠️

Vulnerable?

Find out if your systems are affected. Request a professional assessment.

Get Assessment