CVE Database · CVE-2019-1214
CVSS v3.1
7.8
EPSS
1.32%
Published
Sep 11, 2019
Modified
Oct 29, 2025
CISA Known Exploited Vulnerability
Added: 2021-11-03 · Due: 2022-05-03
Apply updates per vendor instructions.
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (30)
References (3)