CVE-2023-28252: CLFS privilege escalation — ransomware exploitation
A vulnerability in the Common Log File System driver was actively used in Nokoyanya ransomware operations.
A vulnerability in the Common Log File System driver was actively used in Nokoyanya ransomware operations.
CVE-2023-28252 is a privilege escalation vulnerability in the Windows Common Log File System (CLFS) driver. At disclosure it was being actively exploited as a zero-day — Nokoyawa ransomware groups used it to gain SYSTEM access.
The April 2023 update was applied as mandatory to all WS2016–2022 systems. A verification report for our WS2019 servers was obtained via Zabbix.
Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.