← back
CVE-2023-36424

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 12.2%● KEVCWE-125
In short

A flaw in Windows' file system driver allows an attacker with limited local access to gain higher privileges on the system, potentially taking full control. This matters because it bypasses security restrictions designed to keep different user accounts separated.

Technical detail

CWE-125 (Out-of-bounds Read) in the Common Log File System Driver allows local privilege escalation through memory corruption. Attacker requires local code execution capability; successful exploitation grants SYSTEM-level privileges, compromising system integrity and confidentiality.

Summary generated and translated by AI from the official description.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →