logo

Microsoft: Windows CLFS Vulnerability Could Lead to ‘Widespread Deployment and Detonation of Ransomware’

ID: 1eae48d4-388d-560b-bbfd-613b00596898

STIX ID: report--1eae48d4-388d-560b-bbfd-613b00596898

Feed Name: TechRepublic Security

Threat Score
90/100

Date Published: 2025-04-09

Date Updated: 2026-04-23

Author: Fiona Jackson

...
...

**Zero-day CLFS privilege-escalation exploited in the wild leading to ransomware by Storm-2460 (RansomEXX).** Microsoft reported CVE-2025-29824 in the Windows CLFS driver being exploited to escalate standard-user access to SYSTEM, enabling deployment of PipeMagic (remote control/malware) and subsequent ransomware that encrypts files and drops a ransom note (!_READ_ME_REXX2_!.txt); exploitation involved certutil/MSBuild to load an encrypted payload, token overwrites via dllhost.exe, LSASS memory dumping with procdump, and observed IOCs including a compromised Azure-hosted domain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.