HIGH

CVE-2023-36424

Microsoft Windows 10 1507 2023-11-14 CVSS v3.1
CVSS
7.8
KEV

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Summary dbcve.org

This is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) driver. The flaw allows a local attacker to gain elevated SYSTEM privileges by exploiting improper handling of objects in kernel mode.

Mitigation

Apply the Microsoft security update for CVE-2023-36424 via Windows Update or enterprise patch management systems to address the CLFS driver vulnerability.

Patch Commit

Weakness (CWE)

CWE-125 Out-of-bounds Read

EPSS Score

12.18%
Probability of exploitation in next 30 days
96th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE