CVE-2023-36424
KEVmass1Local Privilege Escalation via Out-of-Bounds Read in Windows CLFS Driver
CISA: Microsoft Windows Out-of-Bounds Read Vulnerability
CVE-2023-36424 is an out-of-bounds read (CWE-125) in the Windows Common Log File System (CLFS) driver, a kernel component responsible for managing log files on Windows. A local attacker who can already execute limited-privilege code on an affected system can trigger the bug through crafted interaction with log file data, with no user interaction required. Successful exploitation yields elevation of privilege, giving the attacker high-privilege (typically SYSTEM-level) control of the host — a common post-exploitation step in broader intrusion and ransomware chains. All branches named in the advisory are affected — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), and Windows Server 2008, 2012, 2016 and 2019 — making this effectively a fleet-wide Windows issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13, confirming exploitation in the wild; EPSS puts the 30-day exploitation probability at 12.2% (96th percentile), while ransomware use is listed as unknown and no public proof-of-concept is known.
What to do: Apply Microsoft's security update for CVE-2023-36424 across all affected Windows 10/11 and Windows Server versions, prioritizing servers and admin workstations where a local SYSTEM-level escalation directly enables lateral movement, and use patch inventory to confirm the cumulative update containing the CLFS fix is installed on every host. Federal agencies must meet the BOD 22-01 remediation deadline (two weeks after the 2026-04-13 KEV addition). Because there is no public proof-of-concept and detections are limited, patching — rather than monitoring — is the primary mitigation.
| Microsoft Windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 21H2, 22H2, 23H2 |
| Microsoft Windows Server | 2008, 2012, 2016, 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H