CVE-2023-28252highunder attackransomwareCWE-122

CVE-2023-28252: high-severity vulnerability in Microsoft Windows 10 Version 1507

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA, has a working public exploit and 2 threat group(s) use it.

ssvc Actcvss 7.8epss 49%
from disclosure to weapon77 days
Published on NVDApr 11
1st PoC+77d
metasploitApr 11
CISA KEVApr 11
exploitation probability
49%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 group(s)11 public exploit(s)
Who exploits it — 2

Groups known to exploit this vulnerability (MITRE ATT&CK attribution).

Action required by CISAfederal deadline: 2023-05-02

Apply updates per vendor instructions.

In short

A flaw in Windows' logging system allows someone to run programs with higher privileges than they should have. An attacker with basic user access could gain administrative control of the computer.

Technical detail

Buffer overflow vulnerability in the Common Log File System (CLFS) driver allows local privilege escalation via improper input validation. Requires user-level access and interaction with the CLFS API; successful exploitation results in arbitrary code execution with SYSTEM privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.