logo

Windows CLFS Zero-Day Vulnerability CVE-2022-37969

ID: e4177bee-16d8-5f46-8bdd-c14ccacb0037

STIX ID: report--e4177bee-16d8-5f46-8bdd-c14ccacb0037

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2025-06-23

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz presents a detailed root-cause analysis of CVE-2022-37969, a Windows Common Log File System (CLFS.sys) zero-day used in the wild for local privilege escalation. The report explains how a specially crafted base log file (BLF) overwrites the SignaturesOffset and bypasses cbSymbolZone validation, causing an out-of-bounds write that corrupts a CClfsContainer pointer and leads to a SYSTEM-level compromise or BSOD; it includes PoC steps, debugging traces, and mitigation (apply Microsoft September patch).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.