ZeroHour

CVE-2023-23376

KEV ransomwaremass

Out-of-Bounds Write Privilege Escalation in Microsoft Windows CLFS Driver

CISA: Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2023-23376 is a heap-based buffer overflow (out-of-bounds write, CWE-122/CWE-787) in the Windows Common Log File System (CLFS) kernel driver. A local attacker with low privileges can trigger the flaw when the driver mishandles CLFS log-file data, with no user interaction required. Successful exploitation elevates the attacker from a low-privileged user to SYSTEM/kernel-level privileges, which is why ransomware operators chain it with other bugs after gaining an initial foothold. All supported Windows 10 (1507, 1607, 1809, 20H2, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2008, 2012, 2016, and 2019 releases as of February 2023 are affected. The flaw is actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on February 14, 2023 with known ransomware use, Microsoft shipped the fix in the February 2023 Patch Tuesday release, and EPSS estimates roughly an 11% probability of exploitation within the next 30 days (96th percentile).

What to do: Apply the Microsoft security updates released on February 14, 2023 (February Patch Tuesday) to every Windows 10, Windows 11, and Windows Server system in the affected version list, prioritizing servers and endpoints exposed to ransomware-prone environments. Verify patch status via update history or vulnerability scanning, since exploitation requires only local low-privileged access and there is no substitution for patching. Given confirmed ransomware chaining, also hunt for signs of post-compromise privilege escalation on hosts that were unpatched before mid-February 2023.

Affected
Microsoft Windows 101507 (all builds prior to the February 2023 security updates)
Microsoft Windows 101607 (all builds prior to the February 2023 security updates)
Microsoft Windows 101809 (all builds prior to the February 2023 security updates)
Microsoft Windows 1020H2 (all builds prior to the February 2023 security updates)
Microsoft Windows 1021H2 (all builds prior to the February 2023 security updates)
Microsoft Windows 1022H2 (all builds prior to the February 2023 security updates)
Microsoft Windows 1121H2 (all builds prior to the February 2023 security updates)
Microsoft Windows 1122H2 (all builds prior to the February 2023 security updates)
Microsoft Windows Server 2008supported releases (all builds prior to the February 2023 security updates)
Microsoft Windows Server 2012supported releases (all builds prior to the February 2023 security updates)
Microsoft Windows Server 2016supported releases (all builds prior to the February 2023 security updates)
Microsoft Windows Server 2019supported releases (all builds prior to the February 2023 security updates)
Estimated exposure
mass~1 billion+ Windows devices (the CLFS driver ships in every listed Windows 10/11 client and Windows Server 2008-2019 release) — CLFS is a core Windows kernel component present on all affected supported Windows versions, and Microsoft has publicly reported more than 1 billion active Windows devices, so essentially the entire supported Windows install base at the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-122, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news