Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.

Published 1 Sep 2026Updated 1 Sep 202614 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.

Affected versions

Windows: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 52270Microsoft Windows 11 23h2 - CLFS.sys Elevation of PrivilegeMilad karimi2025-04-22VerifiedPoC-in-GitHub · MrAle98/CVE-2024-49138-POCPOC exploit for CVE-2024-49138★ 271MrAle982025-01-15CandidatePoC-in-GitHub · bananoname/CVE-2024-49138-POC★ 0bananoname2025-01-21CandidatePoC-in-GitHub · DeividasTerechovas/SOC335-CVE-2024-49138-Exploitation-Detected★ 0DeividasTerechovas2025-03-14CandidatePoC-in-GitHub · CyprianAtsyor/letsdefend-cve-2024-49138-investigationHands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.★ 0CyprianAtsyor2025-04-23CandidatePoC-in-GitHub · Bridg3Ops/SOC335-CVE-2024-49138-Exploitation-Detected★ 0Bridg3Ops2025-05-04CandidatePoC-in-GitHub · onixgod/SOC335-Event-ID-313-CVE-2024-49138-Exploitation-Detected--Lest-Defend-WriteupIn this lab I walked through an end-to-end intrusion that began with an external RDP break-in, used a brand-new CLFS privilege-escalation exploit (CVE-2024–49138), and ended with SYSTEM-level cloud credential harvesting. Below is the story, the evidence, and the lessons I drew from it.★ 0onixgod2025-06-12CandidatePoC-in-GitHub · Zedocun/soc-investigation-powershell-edrfreezeSOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated environment.★ 1Zedocun2026-03-09CandidatePoC-in-GitHub · vettrivel007/CVE-2024-49138★ 0vettrivel0072026-04-04CandidatePoC-in-GitHub · basitsajidapply-stack/SOC-Investigation-CVE-2024-49138Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)★ 0basitsajidapply-stack2026-08-22CandidatePoC-in-GitHub · NadineElliottCyber/SOC335-CVE-2024-49138-InvestigationSOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.★ 0NadineElliottCyber2026-08-29CandidatePoC-in-GitHub · Adisasoc/CVE-2024-49138-SOC-InvestigationSOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege escalation, and incident response.★ 0Adisasoc2026-09-02Candidate