CVE-2023-23376
KEV ransomwaremassOut-of-Bounds Write Privilege Escalation in Microsoft Windows CLFS Driver
CISA: Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
CVE-2023-23376 is a heap-based buffer overflow (out-of-bounds write, CWE-122/CWE-787) in the Windows Common Log File System (CLFS) kernel driver. A local attacker with low privileges can trigger the flaw when the driver mishandles CLFS log-file data, with no user interaction required. Successful exploitation elevates the attacker from a low-privileged user to SYSTEM/kernel-level privileges, which is why ransomware operators chain it with other bugs after gaining an initial foothold. All supported Windows 10 (1507, 1607, 1809, 20H2, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2008, 2012, 2016, and 2019 releases as of February 2023 are affected. The flaw is actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on February 14, 2023 with known ransomware use, Microsoft shipped the fix in the February 2023 Patch Tuesday release, and EPSS estimates roughly an 11% probability of exploitation within the next 30 days (96th percentile).
What to do: Apply the Microsoft security updates released on February 14, 2023 (February Patch Tuesday) to every Windows 10, Windows 11, and Windows Server system in the affected version list, prioritizing servers and endpoints exposed to ransomware-prone environments. Verify patch status via update history or vulnerability scanning, since exploitation requires only local low-privileged access and there is no substitution for patching. Given confirmed ransomware chaining, also hunt for signs of post-compromise privilege escalation on hosts that were unpatched before mid-February 2023.
| Microsoft Windows 10 | 1507 (all builds prior to the February 2023 security updates) |
| Microsoft Windows 10 | 1607 (all builds prior to the February 2023 security updates) |
| Microsoft Windows 10 | 1809 (all builds prior to the February 2023 security updates) |
| Microsoft Windows 10 | 20H2 (all builds prior to the February 2023 security updates) |
| Microsoft Windows 10 | 21H2 (all builds prior to the February 2023 security updates) |
| Microsoft Windows 10 | 22H2 (all builds prior to the February 2023 security updates) |
| Microsoft Windows 11 | 21H2 (all builds prior to the February 2023 security updates) |
| Microsoft Windows 11 | 22H2 (all builds prior to the February 2023 security updates) |
| Microsoft Windows Server 2008 | supported releases (all builds prior to the February 2023 security updates) |
| Microsoft Windows Server 2012 | supported releases (all builds prior to the February 2023 security updates) |
| Microsoft Windows Server 2016 | supported releases (all builds prior to the February 2023 security updates) |
| Microsoft Windows Server 2019 | supported releases (all builds prior to the February 2023 security updates) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-122, CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H