High SEVERITY — Vulnerability

CVE-2023-28252: CLFS privilege escalation — ransomware exploitation

A vulnerability in the Common Log File System driver was actively used in Nokoyanya ransomware operations.

Platform
Windows Server
Version
2019
CVE Record
CVE-2023-28252
CVSS Score
7.8/10
Published
11 April 2023
Views
5
Primary source: Review the official advisory at msrc.microsoft.com Kaynağa Git

Summary

CVE-2023-28252 is a privilege escalation vulnerability in the Windows Common Log File System (CLFS) driver. At disclosure it was being actively exploited as a zero-day — Nokoyawa ransomware groups used it to gain SYSTEM access.

Action

The April 2023 update was applied as mandatory to all WS2016–2022 systems. A verification report for our WS2019 servers was obtained via Zabbix.

Windows Server — Related Advisories

VIEW ALL →