CVE-2026-2636 - Vulnerability Analysis
MediumCVSS: 5.5Last Updated: February 25, 2026
Microsoft Windows - Denial of Service
Published: February 25, 2026Updated: February 25, 2026PoC Available
Overview
Microsoft Windows 11 2024 LTSC and Windows Server 2025 contain a denial of service caused by improper handling of special elements in the CLFS.sys driver, letting unprivileged users trigger system crashes, exploit requires local access.
Severity & Score
Severity: Medium
CVSS Score: 5.5
Impact
Unprivileged users can cause system crashes, leading to denial of service.
Mitigation
Update to Windows 25H2 or later versions including the September 2025 cumulative update.
Related Resources
Details
- CVE ID
- CVE-2026-2636
- Severity
- Medium
- CVSS Score
- 5.5
- Type
- denial_of_service
- Status
- new
CWE
- CWE-159
CVSS Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H