HIGH

CVE-2023-23376

Microsoft Windows 10 1507 2023-02-14 CVSS v3.1
CVSS
7.8
KEV

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Summary dbcve.org

This is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) driver, a kernel-mode log file system driver used by Windows. The vulnerability allows an authenticated attacker to gain elevated privileges, likely by exploiting improper handling of operations within the kernel driver.

Mitigation

Apply the Microsoft security update for CVE-2023-23376, which patches the vulnerability in the Windows CLFS driver. Prioritize patching systems that are exposed or handle sensitive workloads.

Patch Commit

Weakness (CWE)

CWE-122 Heap-based Buffer Overflow
CWE-787 Out-of-bounds Write

EPSS Score

10.85%
Probability of exploitation in next 30 days
95.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE