Microsoft: Windows CLFS Vulnerability Could Lead to ‘Widespread Deployment and Detonation of Ransomware’
ID: 1eae48d4-388d-560b-bbfd-613b00596898
STIX ID: report--1eae48d4-388d-560b-bbfd-613b00596898
Feed Name: TechRepublic Security
**Zero-day CLFS privilege-escalation exploited in the wild leading to ransomware by Storm-2460 (RansomEXX).** Microsoft reported CVE-2025-29824 in the Windows CLFS driver being exploited to escalate standard-user access to SYSTEM, enabling deployment of PipeMagic (remote control/malware) and subsequent ransomware that encrypts files and drops a ransom note (!_READ_ME_REXX2_!.txt); exploitation involved certutil/MSBuild to load an encrypted payload, token overwrites via dllhost.exe, LSASS memory dumping with procdump, and observed IOCs including a compromised Azure-hosted domain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
