Microsoft patched CVE-2025-29824, a high-severity elevation-of-privilege flaw in the Windows Common Log File System (CLFS) driver, after it was used as a local privilege escalation step in ransomware intrusions. Reporting tied the bug to attack chains in which adversaries first obtained access through compromised Cisco ASA devices and then exploited the Windows flaw to gain higher privileges on infected hosts, enabling follow-on ransomware activity. Microsoft listed the issue as a CLFS driver vulnerability in its Security Update Guide, and later technical analyses linked it to malware and intrusion activity associated with groups including Nokoyawa and tooling evolution discussed around PipeMagic and RansomExx incidents.
Reverse-engineering write-ups said the bug stemmed from improper lifetime management of the FILE_OBJECT FsContext2 pointer in CLFS. Researchers found that CClfsRequest::Cleanup() could free a CClfsLogCcb object while other I/O operations still referenced it, creating a use-after-free condition reachable through CLFS functions such as ReadArchiveMetadata. The issue could be triggered through a race between CloseHandle() and DeviceIoControl(), producing a kernel crash such as IRQL_NOT_LESS_OR_EQUAL in ntoskrnl.exe; Microsoft's fix reportedly moved the final release logic from the cleanup path to the close path so the object is freed only after outstanding I/O completes.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
By mid-to-late 2025, public research from STAR Labs and BI.ZONE/Habr described the vulnerability's root cause, reachable CLFS functions, and a race condition involving CloseHandle() and DeviceIoControl(). The analyses explained Microsoft's fix and showed proof-of-concept behavior that could trigger a kernel crash, providing defenders and researchers with deeper technical understanding.
STAR Labs reported that attackers first obtained access through compromised Cisco ASA firewalls and then exploited CVE-2025-29824 on Windows systems to gain higher privileges as part of ransomware attack chains. The write-up also described the bug as a use-after-free involving the CLFS FILE_OBJECT FsContext2 pointer.
Microsoft published security guidance and patches for CVE-2025-29824, an elevation-of-privilege flaw in the Windows Common Log File System Driver. The update made the vulnerability publicly tracked and available for defenders to remediate.
Kaspersky reported that Nokoyawa ransomware intrusions used a previously unknown vulnerability in the Windows Common Log File System driver as a local privilege escalation step after initial access. The activity was documented in Securelist coverage published on 2023-04-14, indicating exploitation in the wild by that time.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
bi.zone
Open sourcehabr.com
Open sourcestarlabs.sg
Open sourcemsrc.microsoft.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.