CVE-2024-49138
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- Published
- Dec 10, 2024
- Updated
- Jun 9, 2026
- Assigning CNA
- microsoft
- Evidence observed
- Dec 10, 2024
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 98.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Sources
10- CVE-2024-49138-POCExploit
Proof-of-concept exploit for CVE-2024-49138 in Windows CLFS.sys, achieving local privilege escalation to system shell via token manipulation.
Detailed incident response walkthrough analyzing CVE-2024-49138 exploitation on Windows, covering process tree analysis, IOC identification, and MITRE ATT&CK mapping for detection and mitigation.
Documented incident response case for CVE-2024-49138 exploitation, featuring log analysis, hash validation, C2 detection, and containment procedures for SOC training.
- CVE-2024-49138-POCExploit
POC exploit for CVE-2024-49138
- CVE-2024-49138-SOC-InvestigationResearch
SOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege escalation, and incident response.
- SOC-Investigation-CVE-2024-49138Informational
Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)
This repo contains PoCs for vulnerable Windows drivers.
SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.
Proof-of-concept exploit for CVE-2024-49138, demonstrating a local privilege escalation vulnerability in Windows Kernel-Mode Driver (win32k.sys).
Milad karimi · windows · Apr 22, 2025
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.