← Vulnerability feed

Vulnerability record · CVE-2023-28252 · published 11 April 2023

CVE-2023-28252: Windows CLFS Driver Heap Buffer Overflow Elevation of Privilege

Microsoft · Windows 10 1507

The Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow and out-of-bounds write. A local attacker who can run code on a vulnerable Windows host can exploit the flaw to gain SYSTEM privileges, making it a reliable post-compromise escalation step.

7.8 CVSS 3.1 High CISA KEV since 11 Apr 2023 Known ransomware use EPSS 49% · top 1.2% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score
49%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
13Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV, has confirmed ransomware use, a public exploit, and a very high EPSS score, so unpatched Windows hosts face immediate risk.

What it is

The Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow and out-of-bounds write. A local attacker who can run code on a vulnerable Windows host can exploit the flaw to gain SYSTEM privileges, making it a reliable post-compromise escalation step.

Impact

An attacker gains full administrative/SYSTEM rights on the affected machine, enabling credential theft, disabling defenses, and lateral movement. Because it is a local privilege escalation, it is typically chained after initial access rather than used to breach a host directly.

Attack surface

Reached locally through the CLFS driver interface; the CVSS vector (AV:L/PR:L/UI:N) indicates the attacker needs low-privilege code execution on the host but no user interaction and no elevated rights beforehand.

Exploitation

It is listed in CISA KEV with a 2023-05-02 remediation due date and is documented as used in ransomware campaigns (Braincipher, Nokoyawa); EPSS 30-day probability is about 0.49 (98.8th percentile), and a public exploit reference exists.

What to do

  • Apply the Microsoft April 2023 security updates for all affected Windows client and server versions immediately.
  • Prioritize patching internet-facing and high-value hosts, and treat any unpatched Windows endpoint as exposed to known ransomware chains.
  • Restrict and monitor local code execution paths (macro, script, and user-writable directories) that attackers use to reach the local escalation stage.
  • Enforce least privilege and application control so low-privilege code execution is harder to obtain in the first place.

Detection

  • Alert on unexpected processes spawning with SYSTEM integrity from non-service parents, especially shortly after user-level execution.
  • Monitor for writes or crashes involving clfs.sys and unusual handle activity to CLFS log files by non-system processes.
  • Hunt for known exploitation artifacts and post-exploitation tooling tied to Braincipher and Nokoyawa ransomware activity.
  • Correlate local privilege escalation events with prior phishing or initial-access alerts on the same host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-28252 to the Known Exploited Vulnerabilities catalog on 11 April 2023 as "Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 2 May 2023.

Ransomware crews whose documented playbooks reference this CVE: