CVE-2025-29824Active Exploitation(microsoft / windows_10_1507)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

6.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-04-29. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Active exploitation appears in 8 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 9 observed days

What's happening

  • Active exploitation reported across 8 signals
  • Exploit tool or code specified in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-05-07); latest day: 1
  • 10 total mentions across 9 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_22h2windows_11_23h2windows_11_24h2windows_server_2008windows_server_2012

2 versions affected across 15 products

Deep dive

Activity timeline10 mentions / 9d
01122Mentions · 2026-02-03: 1Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-04-14: 1Mentions · 2026-05-07: 2Mentions · 2026-05-15: 1Mentions · 2026-06-24: 1Mentions · 2026-07-05: 1Mentions · 2026-09-09: 1Exploit Tool / Code · 2026-07-05: 1Exploit Tool / Code · 2026-09-09: 1Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-05-07: 2Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-07-05: 1Active Exploitation · 2026-09-09: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-05-07: 2Patch / Workaround · 2026-06-24: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-20: 1Technical Details · 2026-04-14: 1Technical Details · 2026-05-07: 2Technical Details · 2026-07-05: 1Technical Details · 2026-09-09: 102-0302-1902-2004-1405-0705-1506-2407-0509-09
Signal classification4 categories
Active Exploitation
770.0%
Disclosure
110.0%
Patch
110.0%
General
110.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-031
Disclosure1
2026-02-191
Active Exploitation1
2026-02-201
Active Exploitation1
2026-04-141
Patch1
2026-05-072
Active Exploitation2
2026-05-151
General1
2026-06-241
Active Exploitation1
2026-07-051
Active Exploitation1
2026-09-091
Active Exploitation1
Full discourse10 posts
  • clearbluejar@clearbluejar
    Disclosure

    Patch diffing + RCA for clfs.sys can awhile. I gave the diff + binary to a local LLM. It mapped the UAF path, race condition, all IOCTLs in <20 min LLMs don't replace the work, they are momentum. New blog post following the UAF trail of CVE-2025-29824: https://clearbluejar.github.io/posts/how-llms-feed-your-re-habit-following-the-uaf-trail-in-clfs/

    Post summary

    The post discusses technical analysis of CVE-2025-29824, detailing a use‑after‑free path, race condition, and IOCTLs, but does not provide a PoC, exploit, patch, or claim of active exploitation.

    3350114678.1K
    2.0K followersView on X
  • The DFIR Report@TheDFIRReport
    Active Exploitation

    SEO poisoning ➡️ Fake RVTools ➡️ Python backdoor ➡️ PipeMagic ➡️ CVE-2025-29824 ➡️ #Ransomexx — domain-wide in <19 hrs. The Python backdoor connected to azure-secure-agent[.]com (87.251.67[.]241), enabling cmd/PowerShell exec, payload download, screenshots, and IP discovery. https://t.co/qC4P3wdOVf

    Post summary

    CVE-2025-29824 is being actively exploited by a Ransomexx Python backdoor, enabling remote command execution and data capture across domains within 19 hours.

    2903663.1K
    64.7K followersView on X
  • The DFIR Report@TheDFIRReport
    Active Exploitation

    🔒 Private DFIR Report: Fake RVTools Installer Leads to PipeMagic, CLFS Exploit, and Ransomexx From an SEO-poisoned RVTools search to a custom Python backdoor, PipeMagic via MSBuild, CVE-2025-29824, and Ransomexx, this intrusion went from initial access to domain-wide in under 19 hours. The backdoor beaconed to azure-secure-agent[.]com (87[.]251[.]67[.]241) for remote command execution and payload delivery. Request access or a demo 👉 https://buff.ly/431UFIv #DFIR #ThreatIntel

    Post summary

    The report confirms that CVE‑2025‑29824 was actively exploited in the wild, using a custom Python backdoor and PipeMagic via MSBuild, resulting in a rapid domain‑wide compromise.

    1201852.7K
    70.2K followersView on X
  • 𝕡𝕨𝕟𝕚𝕖@0xpwnie
    Active Exploitation

    CLFS, Windows logging system used for ransomware... The Windows Common Log File System driver has been exploited repeatedly for privilege escalation. CVE-2025-29824 is the most recent: ransomware operators used it to escalate from regular user to SYSTEM by abusing the kernel driver responsible for logging. The execution chain used certutil, a legitimate Windows certificate tool, to download the payload from a compromised third-party site. MSBuild, another legitimate Windows tool, decrypted and ran it. No third-party software touched the attack chain.

    Post summary

    The Windows CLFS driver vulnerability CVE‑2025‑29824 is being actively exploited by ransomware actors, using a chain that leverages certutil and MSBuild to download, decrypt, and execute malicious payloads.

    1112022.8K
    6.5K followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The provided text only includes a list of CVE identifiers with no additional context or detail.

    10000106
    15 followersView on X
  • CiberInteligencia Chile@esecintelcl
    Active Exploitation

    ⚠️ Ojo con CVE-2025-29824: ya está siendo explotado por grupos de ransomware. ✅ Mitigación mientras llega el parche: deshabilitar CLFS si no es crítico o restringir privilegios de ejecución. 📌 Priorizar actualización en servidores y equipos expuestos a internet. #ZeroDay #CVE

    Post summary

    CVE-2025-29824 is already being used by ransomware groups; the post urges disabling CLFS or restricting privileges as interim mitigation while awaiting a vendor patch.

    000101.1K
    24 followersView on X
  • CiberInteligencia Chile@esecintelcl
    Active Exploitation

    🚨 ALERTA ZERO-DAY CVE-2025-29824: escalada de privilegios 0-day en controlador CLFS de Windows. Activamente explotado por ransomware para obtener acceso SYSTEM. ✔️ Confirmado por CISA ⚠️ Windows 10, 11, Server 2019/2022 vulnerables 📅 Parche obligatorio para agencias federales. https://t.co/xzS2lpB3Hc

    Post summary

    CVE‑2025‑29824 is a confirmed zero‑day privilege‑escalation bug in Windows’ CLFS controller, actively exploited by ransomware on Windows 10, 11, and Server 2019/2022; CISA has confirmed its use and a mandatory patch is required for federal agencies.

    100001.0K
    24 followersView on X
  • CyberWarZone@cyberwarzo44531
    Patch

    Microsoft’s April 2026 Patch Tuesday fixes 134 vulnerabilities, including a zero-day (CVE-2025-29824) actively exploited, enabling SYSTEM privilege escalation via CLFS. #CyberSecurity #ZeroDay #PatchTuesday

    Post summary

    Microsoft released its April 2026 Patch Tuesday update, addressing 134 CVEs, including the actively‑exploited CVE‑2025‑29824 that allows SYSTEM privilege escalation via CLFS.

    00010192
    28 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    @vuln_tracker @TheDFIRReport 🚨 **CVE-2025-29824** is a privilege escalation vulnerability in the Windows **Common Log File System (CLFS)** that has been actively exploited in cyberattacks. #CyberSecurity #Vulnerability

    Post summary

    CVE-2025-29824 is a privilege escalation flaw in Windows CLFS that has been actively exploited in cyberattacks.

    1000054
    311 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    AI has accelerated vulnerability exploitation from 53 days to just 8 hours between disclosure and active exploitation. Attackers now weaponize CVE-2025-29824 and similar flaws almost immediately, moving laterally through compromised environments before organizations can patch. Runtime segmentation helps contain post-compromise activity when patching falls behind. #ZeroDay #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/the-exploit-doesnt-exist-you-can-still-prove-it-works-against-you-2026

    Post summary

    The post indicates that AI has accelerated the exploitation of CVE-2025-29824, with attackers deploying the flaw within hours of disclosure, demonstrating active exploitation in the wild.

    0000064
    1.9K followersView on X
CPE platform detail27 entries

27 of 27 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_22h2--arm64
OSmicrosoftwindows_11_22h2--x64
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more