CVE-2022-24481 is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) driver. The provided content identifies the affected component and class of issue but does not include technical details such as the specific vulnerable function, root cause, or exploitation primitive. Microsoft assigned it a CVSS v3 score of 7.8 and rated exploitation as more likely.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a local Windows kernel privilege-escalation PoC for CVE-2022-24481 targeting CLFS (Common Log File System). It provides two separate PoCs: one for Windows 10 (win10_poc/) and one for Windows 11 (win11_poc/), both implemented in C++ and intended to be built with Visual Studio 2022 (v143) and Windows SDK 10.0. High-level capability: the exploit crafts and modifies CLFS BLF log files (e.g., MyMiniLog*.blf) and uses CLFS APIs (CreateLogFile/AddLogContainer) plus a final trigger via NtSetInformationFile on the CLFS log handle to reach a vulnerable kernel code path. The exploitation goal is to obtain kernel read/write capability sufficient to perform token stealing: replace the current process EPROCESS->Token with the System (PID 4) token, resulting in SYSTEM privileges and launching an elevated command prompt. Win10 flow (win10_poc/win10_poc.cpp + win10_poc/token_operations.h): - Creates a CLFS log (log:MyMiniLog) and container file ("1"), maps current directory to drive X: (SetupMapping("X:", currentDir)), parses and modifies MyMiniLog.blf to inject a crafted NT path (\\??\\X:\\1) and a fake vtable pointer (0x50000). - Computes kernel function addresses (ClfsEarlierLsn from CLFS.SYS and SeSetAccessStateGenericMapping from ntoskrnl.exe) and prepares fake objects/vtable (Memory_prepare). - Uses the vulnerability to corrupt the current thread’s PreviousMode (KTHREAD->PreviousMode) to 0 (kernel mode), enabling NtReadVirtualMemory/NtWriteVirtualMemory with (HANDLE)-1 to access kernel memory. - token_operations.h then locates current EPROCESS from ETHREAD (PreviousModeAddress-0x232, then ETHREAD+0x220/0x210), walks ActiveProcessLinks to find PID 4, reads System token, and overwrites the current process token field (offset chosen by build, commonly 0x4B8/0x358). Restores PreviousMode to 1 and spawns cmd. Win11 flow (win11_poc/win11_poc.cpp + win11_poc/kernel_utils.h): - Creates two CLFS logs/containers (log:MyMiniLog1/2, containers "1"/"2"), maps X: to current directory, modifies both MyMiniLog1.blf and MyMiniLog2.blf similarly (fake vtable pointer 0x50000). - Initializes a pipe-based kernel R/W helper (pipe_arbitrary_rw.h; not included in the provided file list but referenced), then uses the CLFS trigger twice: first to read kernel memory at the System token field address, then to write that token value into the current process token field. - Token field addresses are derived by leaking kernel object addresses via SystemExtendedHandleInformation and applying a build-dependent token offset. Notable observables/endpoints: no network IOCs. The code interacts with CLFS pseudo-files (log:MyMiniLog*), creates/deletes local container files ("1", "2"), reads/writes BLF files in the working directory (MyMiniLog*.blf), creates a DOS device mapping for X:, and loads local system binaries (C:\Windows\System32\drivers\CLFS.SYS, ntoskrnl.exe) for address calculations. Overall structure/purpose: a practical LPE exploit PoC demonstrating CLFS log file corruption leading to kernel memory manipulation and SYSTEM token theft on specific Windows 10/11 builds.
This repository contains a proof-of-concept (POC) exploit for CVE-2022-24481, a local privilege escalation vulnerability in the Microsoft Windows CLFS (Common Log File System) driver. The main file, 'CVE-2022-24481-POC.cpp', is a C++ program that manipulates kernel memory structures related to CLFS containers to achieve arbitrary code execution in kernel context. The exploit works by crafting and modifying log files and memory structures, ultimately replacing process tokens to escalate privileges. Upon successful exploitation, it spawns a SYSTEM-level command shell (cmd.exe). The exploit uses several temporary files in the 'C:\Users\Public\' directory and interacts with the CLFS driver via Windows API calls. The README provides technical background and reverse engineering notes, confirming the exploit's focus on the CLFS container pointer manipulation vulnerability. This is a local exploit and does not expose network endpoints.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.