EXPOSURES › CVE-2021-36955
CVE-2021-36955
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA Microsoft Windows CLFS driver vulnerability allows privilege escalation, actively exploited and linked to ransomware attacks.
The Microsoft Windows CLFS driver contains a privilege escalation vulnerability, actively exploited in the wild and associated with ransomware campaigns. DIB organizations using Windows must promptly patch to prevent attackers from gaining elevated system access. Failure to patch exposes systems to potential data breaches and compliance violations (NIST 800-171 controls 3.a, 3.d, 4.a).
Shame score — The vulnerability's active exploitation by ransomware groups demonstrates a significant security failure with potentially widespread impact, despite being a known issue.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
"Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation."
"CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability"
"Microsoft Exchange hack, explained"
"NVD - CVE-2021-26855"
"2021 Microsoft Exchange Server data breach"
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |