Microsoft says the RansomEXX ransomware serious zero-day vulnerability in the Windows Common Log File System (CLFS) gang is exploiting a to gain SYSTEM privileges on victims' machines.

The vulnerability is tracked as CVE-2025-29824 and was fixed in this month's Patch Tuesday. It is a use-after-free, which allows local attackers with low privileges to gain SYSTEM privileges. Attacks can be simple and require no user interaction.
See also: State Bar of Texas: Data breach by INC ransomware gang?
While the company has issued security updates for the affected versions of Windows, it said that updates for Windows 10 x64 and 32-bit systems will be released as soon as possible.
Although the RansomEXX using the Windows vulnerability were limited, the targets were mainly:
- organizations in the information technology (IT) and real estate sectors in the US
- organizations in the financial sector in Venezuela
- a Spanish software company
- organizations in the retail sector in Saudi Arabia
“Customers running Windows 11, version 24H2 are not affected by the observed exploit, even if the vulnerability existed. Microsoft urges customers to apply these updates as soon as possible“.
See also: Hunters International: Focuses on data theft – The end of ransomware?
Microsoft has linked these attacks to the ransomware gang , which it tracks as Storm-2460. The attackers installed the PipeMagic backdoor on compromised systems, which was used to deploy the CVE-2025-29824 exploit, ransomware payloads, and !READ_ME_REXX2!.txt ransom notes after encrypting files.
PipeMagic was discovered by Kaspersky in 2022. The malware can collect sensitive data, provides full remote access to infected devices, and allows attackers to deploy additional malicious payloads to spread across networks.
See also: Highline Schools ransomware incident breached thousands of data

As we mentioned earlier, Microsoft fixed the zero-day vulnerability in Windows CLFS with Patch Tuesday April 2025.In addition to this vulnerability, however, it fixed 120+ other bugs. You can see them in brief below:
- 49 vulnerabilities that allow privilege escalation
- 31 vulnerabilities that allow remote code execution
- 17 vulnerabilities that allow information disclosure
- 14 vulnerabilities that allow Denial of Service attacks
- 9 vulnerabilities that allow bypassing security features
- 3 vulnerabilities that allow spoofing
Source: www.bleepingcomputer.com
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
