Microsoft has confirmed active exploitation of two severe vulnerabilities within the Windows Common Log File System (CLFS) driver, enabling attackers to escalate their privileges to SYSTEM-level access on affected machines.
Tracked as CVE-2025-32706 and CVE-2025-32701, these vulnerabilities were addressed in the May 2025 Patch Tuesday update, released on May 13, 2025.
Severe Vulnerabilities Under Active Attack
Both vulnerabilities provide threat actors with the ability to elevate their privileges locally to the highest system level, allowing them to gain full control over compromised devices. CVE-2025-32706 results from improper input validation in the CLFS driver, while CVE-2025-32701 is identified as a use-after-free flaw within the same component.
The vulnerability CVE-2025-32701 was discovered by researchers at the Microsoft Threat Intelligence Center (MSTIC), while CVE-2025-32706 was identified through collaboration between Benoit Sevens of Google Threat Intelligence and the CrowdStrike Advanced Research Team.
“These vulnerabilities pose a critical threat, as they enable attackers to gain unrestricted access to systems,” explained a Microsoft security engineer. “Exploitation allows attackers to perform any action, from deploying ransomware to stealing sensitive data.”
This follows a similar trend from earlier in the year, where another CLFS vulnerability, CVE-2025-29824, was found to be exploited in ransomware attacks targeting various industries. CLFS vulnerabilities have become a growing concern, with 32 such flaws addressed since 2022, averaging approximately 10 patches per year.
“The CLFS component remains a prime target due to its deep integration within the Windows kernel and its widespread presence across systems,” said a Microsoft security researcher.
Connection to Ransomware Campaigns
Historically, CLFS vulnerabilities have been leveraged in ransomware attacks. In April 2025, Microsoft reported that exploitation of a CLFS zero-day vulnerability led to the deployment of ransomware across several industries, including IT, real estate, and finance, affecting entities in the United States, Venezuela, Spain, and Saudi Arabia.
The typical attack process involves threat actors gaining access to a system, then utilizing CLFS flaws to escalate privileges before executing ransomware or other malicious software.
Security experts urge organizations to apply the May 2025 Patch Tuesday updates as soon as possible to mitigate these risks.
“Elevation of privilege vulnerabilities play a pivotal role in modern cyberattacks,” said a representative from Microsoft’s Security Response Center. “Applying these patches is essential to building a strong defense, even if attackers manage to breach initial system defenses.”
Organizations should also adopt additional security strategies, such as enhanced monitoring for suspicious behavior, restricting administrative access, and ensuring robust backup systems to minimize the impact of any successful attacks.




