CVE-2025-29824 is a patched Windows zero-day in CLFS (clfs.sys) exploited by the Balloonfly group to escalate privileges and deploy Play ransomware and Grixba malware.| Ampcus Cyber