CVE-2021-43224
MEDIUMWindows Common Log File System Driver - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-43224. PoCs published by KaLendsi.
AI-analyzed exploit summary This PoC exploits a vulnerability in the Windows Common Log File System (CLFS) driver, leading to a Blue Screen of Death (BSOD). It demonstrates improper handling of log file operations, specifically through `CreateLogFile` and `GetLogFileInformation` calls.
Description
Windows Common Log File System Driver Information Disclosure Vulnerability
Exploits (1)
nomisec
WORKING POC
95 stars
by KaLendsi · poc
https://github.com/KaLendsi/CVE-2021-43224-POC
This PoC exploits a vulnerability in the Windows Common Log File System (CLFS) driver, leading to a Blue Screen of Death (BSOD). It demonstrates improper handling of log file operations, specifically through `CreateLogFile` and `GetLogFileInformation` calls.
Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target:
Windows Common Log File System Driver (CLFS) on Windows 20H2 (19042.1387)
No auth needed
Prerequisites:
Access to a vulnerable Windows system with CLFS driver
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-43224
Scores
CVSS v3
5.5
EPSS
0.0387
EPSS Percentile
88.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (20)
microsoft/windows_10
microsoft/windows_10
20h2
microsoft/windows_10
21h1
microsoft/windows_10
1607
microsoft/windows_10
1809
microsoft/windows_10
1909
microsoft/windows_10
2004
microsoft/windows_11
microsoft/windows_7
microsoft/windows_8.1
... and 10 more
Published
Dec 15, 2021
Tracked Since
Feb 18, 2026