Microsoft Windows Server 2012
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*
This vulnerability is being actively exploited in the wild.
A use-after-free vulnerability has been identified in the Windows Common Log File System Driver. This vulnerability allows an authorized attacker to locally elevate privileges. The issue arises from improper memory management, which can be exploited to gain higher-level permissions, potentially leading to unauthorized actions or access within the system.
Exploitation of this vulnerability allows an attacker to gain SYSTEM privileges.
Users can apply the security update KB5058403 or KB5058451, available through the Microsoft Update Catalog, to address this vulnerability. Instructions for downloading these updates can be found on the Microsoft Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.