logo

Exploitation of CLFS zero-day leads to ransomware activity

ID: 74e9dcc1-b5a3-5939-9a37-5da7dcb76594

STIX ID: report--74e9dcc1-b5a3-5939-9a37-5da7dcb76594

Feed Name: Microsoft Security

Threat Score
88/100

Date Published: 2025-04-08

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft discovered active exploitation of a zero-day Windows Common Log File System (CLFS) privilege-escalation vulnerability (CVE-2025-29824) that was used in limited targeted intrusions by the Storm-2460 actor. Attackers deployed the PipeMagic backdoor, launched an in-memory CLFS exploit to obtain SYSTEM privileges, dumped LSASS to harvest credentials, and then executed ransomware; Microsoft provides indicators, Sentinel hunting queries, and mitigation/patching guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.