Junglewise Threat Intelligence

CVE-2023-28252: Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

CVE-2023-28252 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-04-11

Technologies: Microsoft Windows Server 2008, Microsoft Windows, Microsoft Windows 11, Microsoft Windows Server 2012, Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

An out-of-bounds write vulnerability in the Microsoft Windows Common Log File System (CLFS) driver allows a local attacker to gain elevated privileges. The flaw stems from a heap-based buffer overflow that can be exploited to execute code with SYSTEM privileges.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 20H2, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2022

Timeline

  • 2023-04-11: disclosed
  • 2023-04-11: advisory
  • 2023-04-11: patched
  • 2023-04-11: kev added: Added to CISA KEV catalog on the same day as publication.
  • 2023-04-11: exploited: Reported as exploited in the wild at the time of disclosure.

Related threats