CVE-2025-60709
HIGHWindows Common Log File System Driver - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-60709. PoCs published by KONDORDEVSECURITYCORP, ByteCodeSecure.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-60709, a local privilege escalation (LPE) vulnerability in the Windows Common Log File System (CLFS) driver. The exploit leverages a memory corruption bug to achieve arbitrary kernel write, allowing token theft for SYSTEM privileges.
Description
Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Exploits (2)
This repository contains a functional exploit for CVE-2025-60709, a local privilege escalation (LPE) vulnerability in the Windows Common Log File System (CLFS) driver. The exploit leverages a memory corruption bug to achieve arbitrary kernel write, allowing token theft for SYSTEM privileges.
This repository contains a functional exploit for CVE-2025-60709, a local privilege escalation (LPE) vulnerability in the Windows Common Log File System (CLFS) driver. The exploit leverages a memory corruption bug to achieve arbitrary kernel write, allowing token theft for SYSTEM privileges.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H