← back
CVE-2023-23376

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 10.9%● KEVCWE-122
Vexday Risk Score
56Attention
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 10.9%KEV simPoC Nuclei Metasploit Patch referenciado
Lifecycle
14 Feb 2023Active exploitation (CISA KEV)
14 Feb 2023Published on NVD
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A flaw in Windows' logging system driver allows a user with basic access to gain higher privileges and take full control of the computer. This is dangerous because it lets attackers bypass security restrictions.

Technical detail

A buffer overflow vulnerability in the Common Log File System (CLFS) driver enables local privilege escalation through crafted I/O control requests. An authenticated attacker can trigger memory corruption to execute code with kernel privileges, bypassing normal access controls.

Summary generated and translated by AI from the official description.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →