CVE-2023-28252: high-severity vulnerability in Microsoft Windows 10 Version 1507
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published · Updated
Patch now. It under exploitation confirmed by CISA, has a working public exploit and 2 threat group(s) use it.
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
Apply updates per vendor instructions.
A flaw in Windows' logging system allows someone to run programs with higher privileges than they should have. An attacker with basic user access could gain administrative control of the computer.
Buffer overflow vulnerability in the Common Log File System (CLFS) driver allows local privilege escalation via improper input validation. Requires user-level access and interaction with the CLFS API; successful exploitation results in arbitrary code execution with SYSTEM privileges.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.