← back
CVE-2023-28252

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 49.0%● KEVCWE-122
In short

A flaw in Windows' logging system allows someone to run programs with higher privileges than they should have. An attacker with basic user access could gain administrative control of the computer.

Technical detail

Buffer overflow vulnerability in the Common Log File System (CLFS) driver allows local privilege escalation via improper input validation. Requires user-level access and interaction with the CLFS API; successful exploitation results in arbitrary code execution with SYSTEM privileges.

Summary generated and translated by AI from the official description.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →