Vulnerability record · CVE-2023-23376 · published 14 February 2023
CVE-2023-23376: Windows CLFS driver heap overflow elevation of privilege
Microsoft · Windows 10 1507
The Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow and out-of-bounds write that lets a local user escalate privileges. It affects a broad set of Windows 10, Windows 11 and Windows Server releases, and Microsoft shipped fixes in the February 2023 update cycle. Because CLFS runs in kernel mode, a successful exploit yields SYSTEM-level code execution on the host.
Description
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is confirmed exploited in the wild and tied to ransomware use, but it requires local access and low privileges, so it is a high-priority patch rather than a remotely exploitable critical.
What it is
The Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow and out-of-bounds write that lets a local user escalate privileges. It affects a broad set of Windows 10, Windows 11 and Windows Server releases, and Microsoft shipped fixes in the February 2023 update cycle. Because CLFS runs in kernel mode, a successful exploit yields SYSTEM-level code execution on the host.
Impact
An attacker who already has a foothold on the machine gains kernel-level code execution and full SYSTEM privileges, enabling credential theft, disabling of security controls and lateral movement. CISA flags the flaw as used in ransomware campaigns, so the practical outcome is host takeover feeding broader intrusion activity.
Attack surface
The CVSS vector is local (AV:L), low complexity, low privileges required and no user interaction, so the flaw is reached by running code on the target host rather than over the network. No remote or unauthenticated path is described in the record.
Exploitation
CVE-2023-23376 is listed in CISA's Known Exploited Vulnerabilities catalog with a due date of 2023-03-07 and known ransomware campaign use, and EPSS gives a 30-day probability of roughly 10.9 percent (95.6th percentile). The record contains no public exploit reference beyond the vendor advisory and KEV entry.
What to do
- Apply the Microsoft February 2023 security updates for all affected Windows 10, Windows 11 and Windows Server versions as the first action.
- Prioritize patching of internet-facing and high-value hosts, and treat any unpatched endpoint as compromised-capable given KEV status.
- Restrict local logon and interactive access so low-privileged users cannot run arbitrary code on sensitive systems.
- Enable and tune EDR/AV kernel-level exploit protections and monitor for CLFS abuse patterns on unpatched hosts.
- Track KEV remediation deadlines and verify patch compliance across the full affected product list.
Detection
- Alert on unexpected processes loading or interacting with clfs.sys and on anomalous writes to CLFS log files (.blf) outside normal system activity.
- Monitor for privilege escalation behavior: processes spawning with SYSTEM integrity from user-writable paths or unusual parent-child relationships.
- Hunt for known CLFS exploit artifacts and crash dumps referencing clfs.sys or heap corruption in the kernel driver.
- Correlate local privilege escalation alerts with ransomware precursor activity such as credential dumping and security tool tampering.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-23376 to the Known Exploited Vulnerabilities catalog on 14 February 2023 as "Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 7 March 2023.
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23376 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23376 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-23376 | US Government Resource |
Track CVE-2023-23376 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-23376), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.