{
  "CVE": "CVE-2025-32701",
  "severity": "high",
  "cvss_score": "7.8/10",
  "description": "Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
  "exploitation_status": "CISA confirms active exploitation in the wild.",
  "epss_probability": "1.29%",
  "metrics": {
    "cvss": "3.1",
    "impact_vector": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
  },
  "weakness_enumeration": {
    "CWE": "[CWE-416](https://cwe.mitre.org/data/definitions/416.html)"
  },
  "affected_software": [
    { "Vendor": "Microsoft", "Product": "Windows 10 1507", "Versions": "< 10.0.10240.21014", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows 10 1607", "Versions": "< 10.0.14393.8066", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows 10 1809", "Versions": "< 10.0.17763.7314", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows 10 21h2", "Versions": "< 10.0.19044.5854", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows 10 22h2", "Versions": "< 10.0.19045.5854", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows 11 22h2", "Versions": "< 10.0.22621.5335", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows 11 23h2", "Versions": "< 10.0.22631.5335", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows 11 24h2", "Versions": "< 10.0.26100.3981", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows Server 2008", "Versions": "All versions", "Update": "Sp2" },
    { "Vendor": "Microsoft", "Product": "Windows Server 2008", "Versions": "r2", "Update": "Sp1" },
    { "Vendor": "Microsoft", "Product": "Windows Server 2012", "Versions": "All versions", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows Server 2012", "Versions": "r2", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows Server 2016", "Versions": "< 10.0.14393.8066", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows Server 2019", "Versions": "< 10.0.17763.7314", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows Server 2022", "Versions": "< 10.0.20348.3692", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows Server 2022 23h2", "Versions": "< 10.0.25398.1611", "Update": "—" },
    { "Vendor": "Microsoft", "Product": "Windows Server 2025", "Versions": "< 10.0.26100.3981", "Update": "—" }
  ],
  "timeline": {
    "published": "May 13, 2025",
    "last_modified": "Jun 17, 2026",
    "status": "Analyzed"
  },
  "faq": [
    {
      "question": "What is CVE-2025-32701?",
      "answer": "Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally."
    },
    {
      "question": "How severe is CVE-2025-32701?",
      "answer": "CVE-2025-32701 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 1.29% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog."
    },
    {
      "question": "How do I fix CVE-2025-32701?",
      "answer": "Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected."
    }
  ],
  "references": [
    "[Vendor Advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32701)",
    "[US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32701)"
  ]
}
