Safeguard
Vulnerability Analysis

The Windows CLFS Driver Produced a Second Confirmed-Exploited CVE, Two Years Apart

CVE-2023-36424 and CVE-2021-43226 both hit the same Windows Common Log File System Driver, one carrying a confirmed ransomware association, plus a separate Desktop Window Manager information leak.

Safeguard Research Team
5 min read

Three more Microsoft Windows vulnerabilities were confirmed exploited over the past year, and two of them — four years apart in original disclosure date — trace back to the exact same kernel driver. This is another additional Microsoft finding beyond the clusters already covered in this series (the ancient 2008-2013 batch, WSUS/Configuration Manager, SharePoint/Exchange, Defender, and the nine-CVE Windows privilege-escalation set): CVE-2023-36424 and CVE-2021-43226 both hit the Windows Common Log File System (CLFS) Driver, while CVE-2026-20805 is a separate Desktop Window Manager information-disclosure bug.

CVECVSSComponentAdded to KEVRansomware use
CVE-2021-432267.8CLFS Driver6 Oct 2025Known
CVE-2023-364247.8CLFS Driver13 Apr 2026Unknown
CVE-2026-208055.5Desktop Window Manager13 Jan 2026Unknown

Why the same driver producing two confirmed-exploited CVEs, years apart, is worth flagging on its own

CVE-2021-43226 was originally disclosed in December 2021. CVE-2023-36424 was disclosed nearly two years later, in November 2023. Both describe an elevation-of-privilege weakness in the Windows Common Log File System Driver — the kernel component Windows uses to write structured transaction logs — and both were confirmed as actively exploited by CISA, one in October 2025 and the other in April 2026, roughly six months apart on the KEV timeline despite a two-year gap in their original NVD publication dates. CLFS has a well-documented history as a productive target for local-privilege-escalation research precisely because it runs in kernel mode and processes complex, attacker-influenced log-file structures — the same category of design that makes a component attractive to vulnerability researchers and attackers alike, repeatedly, across multiple disclosed bugs rather than just one. Two separate CVEs against the identical driver, both eventually confirmed exploited, is evidence that whatever made CLFS attractive to attackers in 2021 was still attractive to a different set of attackers in 2023 — the underlying design of the component did not become safer between researchers finding the first bug and researchers finding the second.

CVE-2021-43226 also carries CISA's "Known" ransomware designation, a flag reserved for vulnerabilities CISA has independently determined ransomware operators have incorporated into their toolkits — meaningfully different from the CVSS score alone, since it describes not just how severe the bug is on paper but whether it has already been folded into working criminal operational playbooks. A local privilege-escalation bug is rarely a ransomware operator's initial entry point, but it is exactly the kind of tool that turns a single-endpoint foothold gained through phishing or a leaked credential into full local administrative control — the step that comes right before encryption and lateral movement across a network.

The DWM information-disclosure bug is a different animal, and a smaller one

CVE-2026-20805 sits in Desktop Window Manager, not CLFS, and is classified as CWE-200 (exposure of sensitive information), scoring a comparatively modest 5.5. Its CVSS vector shows local access and low privileges required, with confidentiality impact alone — no integrity or availability effect. On its own, an information-disclosure bug rarely makes headlines. But paired with an elevation-of-privilege bug like either CLFS CVE, an information leak from a component like DWM — which handles window composition and can hold sensitive rendering data in memory — is exactly the kind of secondary building block that helps an attacker refine a chained local-privilege-escalation attempt rather than standing on its own as the primary weapon. CISA's decision to add a 5.5-severity local information-disclosure bug to KEV at all is itself a signal: exploitation was confirmed, regardless of the raw severity number, and confirmed exploitation is the criterion that puts something in this catalogue in the first place — CVSS score is a secondary consideration.

What to check this week

Verify the patch levels closing both CLFS driver CVEs specifically, not just "the latest cumulative update" as a proxy. Given the two-year gap between these bugs' original disclosure dates, an endpoint could plausibly have received a fix for one without ever receiving the fix for the other if patching cadence was inconsistent across that period.

Treat any endpoint still missing the CVE-2021-43226 fix as a heightened-priority finding, given its confirmed ransomware association — this is not a theoretical risk category but one CISA has tied to active criminal tooling.

Review DWM-related process behavior for anomalies where security telemetry allows it, since an information-disclosure bug in this component is more useful to an attacker as reconnaissance than as a headline event on its own.

Cross-reference these findings against the nine-CVE Windows privilege-escalation cluster covered elsewhere in this series — CLFS driver bugs belong to the same broad local-elevation category, and an organization's remediation tracking should treat all of them as one continuous risk surface rather than as isolated one-off patches.

A final consideration on driver-level bugs versus application-level bugs

Kernel driver vulnerabilities like the CLFS pair carry a different remediation cost than an application patch: a driver update typically requires a reboot, and in some enterprise change-management processes, driver-level updates get routed through a slower approval path than an application patch would. That slower path is exactly the kind of friction that can leave a confirmed-exploited, ransomware-associated bug unpatched for longer than its severity score alone would suggest is acceptable.

How Safeguard helps

Safeguard's continuous inventory distinguishes kernel-level driver vulnerabilities from application-layer findings and tracks confirmed ransomware association as a first-class signal — surfacing a case like CVE-2021-43226's CLFS driver bug with the urgency its criminal-tooling association warrants, rather than letting it blend into a generic backlog of Windows patches sorted by CVSS score alone.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.