HIGH
CVE-2023-36424
CVSS
7.8
KEV
Description
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Summary dbcve.org
This is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) driver. The flaw allows a local attacker to gain elevated SYSTEM privileges by exploiting improper handling of objects in kernel mode.
Mitigation
Apply the Microsoft security update for CVE-2023-36424 via Windows Update or enterprise patch management systems to address the CLFS driver vulnerability.
Weakness (CWE)
CWE-125
Out-of-bounds Read
EPSS Score
12.18%
Probability of exploitation in next 30 days
96th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.