KEV · Actively exploited
CVE-2025-29824
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability
EPSS
0.92%
above median
percentile 76.4%
CISA Known Exploited Vulnerability
- Added to KEV
- 2025-04-08
- Remediation deadline
- 2025-04-29
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware
- Yes, known ransomware campaign
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Fixed in Windows Server 2025 (Server Core installation) 10.0.26100.3775 Windows Server 2025 10.0.26100.3775 Windows Server 2022 (Server Core installation) 10.0.20348.3453 Windows Server 2022 10.0.25398.1551 Windows Server 2019 (Server Core installation) 10.0.17763.7136 Windows Server 2019 10.0.17763.7136 Windows Server 2016 (Server Core installation) 10.0.14393.7969 Windows Server 2016 10.0.14393.7969 Windows 11 24H2 · 2024-H2 10.0.26100.3775 Windows 11 23H2 · 2023-H2 10.0.22631.5189 Windows 11 22H2 · 2022-H2 10.0.22621.5189 Windows 10 22H2 · 2022-H2 10.0.19045.5737 Windows 10 21H2 · 2021-H2 10.0.19044.5737 Windows 10 1809 · 2018-09 10.0.17763.7136 Windows 10 1607 · 2016-07 10.0.14393.7969