Junglewise Threat Intelligence

CVE-2023-23376: Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

CVE-2023-23376 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-02-14

Technologies: Microsoft Windows Server 2008, Microsoft Windows, Microsoft Windows 11, Microsoft Windows Server 2012, Microsoft Windows Server 2022, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

A privilege escalation vulnerability exists in the Microsoft Windows Common Log File System (CLFS) driver due to a heap-based buffer overflow. An attacker who successfully exploits this vulnerability could gain SYSTEM privileges. The vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Windows 10 up to (excluding) 10.0.10240.19747
  • Microsoft Windows 11 21H2, 22H2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2022

Timeline

  • 2023-02-14: disclosed
  • 2023-02-14: patched
  • 2023-02-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-02-14: exploited

Related threats