What happened
Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.
Affected versions
Windows: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 52270Microsoft Windows 11 23h2 - CLFS.sys Elevation of PrivilegeMilad karimi2025-04-22VerifiedPoC-in-GitHub · MrAle98/CVE-2024-49138-POCPOC exploit for CVE-2024-49138★ 271MrAle982025-01-15CandidatePoC-in-GitHub · bananoname/CVE-2024-49138-POC★ 0bananoname2025-01-21CandidatePoC-in-GitHub · DeividasTerechovas/SOC335-CVE-2024-49138-Exploitation-Detected★ 0DeividasTerechovas2025-03-14CandidatePoC-in-GitHub · CyprianAtsyor/letsdefend-cve-2024-49138-investigationHands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.★ 0CyprianAtsyor2025-04-23CandidatePoC-in-GitHub · Bridg3Ops/SOC335-CVE-2024-49138-Exploitation-Detected★ 0Bridg3Ops2025-05-04CandidatePoC-in-GitHub · onixgod/SOC335-Event-ID-313-CVE-2024-49138-Exploitation-Detected--Lest-Defend-WriteupIn this lab I walked through an end-to-end intrusion that began with an external RDP break-in, used a brand-new CLFS privilege-escalation exploit (CVE-2024–49138), and ended with SYSTEM-level cloud credential harvesting. Below is the story, the evidence, and the lessons I drew from it.★ 0onixgod2025-06-12CandidatePoC-in-GitHub · Zedocun/soc-investigation-powershell-edrfreezeSOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated environment.★ 1Zedocun2026-03-09CandidatePoC-in-GitHub · vettrivel007/CVE-2024-49138★ 0vettrivel0072026-04-04CandidatePoC-in-GitHub · basitsajidapply-stack/SOC-Investigation-CVE-2024-49138Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)★ 0basitsajidapply-stack2026-08-22CandidatePoC-in-GitHub · NadineElliottCyber/SOC335-CVE-2024-49138-InvestigationSOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.★ 0NadineElliottCyber2026-08-29CandidatePoC-in-GitHub · Adisasoc/CVE-2024-49138-SOC-InvestigationSOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege escalation, and incident response.★ 0Adisasoc2026-09-02CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.