HIGH

CVE-2023-28252

Microsoft Windows 10 1507 2023-04-11 CVSS v3.1
CVSS
7.8
KEV

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Summary dbcve.org

An elevation of privilege vulnerability in the Windows Common Log File System (CLFS) driver allows a local attacker to gain SYSTEM-level privileges by exploiting a flaw in the kernel-mode driver.

Mitigation

Apply the Microsoft security update for CVE-2023-28252 (April 2023 Patch Tuesday) to all affected Windows systems; prioritize endpoint and server systems where untrusted local users may have access.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-122 Heap-based Buffer Overflow
CWE-787 Out-of-bounds Write

EPSS Score

48.97%
Probability of exploitation in next 30 days
98.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE