Vulnerability record · CVE-2023-36424 · published 14 November 2023
CVE-2023-36424: Windows Common Log File System Driver out-of-bounds read privilege escalation
Microsoft · Windows 10 1507
CVE-2023-36424 is an out-of-bounds read (CWE-125) in the Windows Common Log File System (CLFS) driver that allows elevation of privilege. It affects a broad set of Windows 10, Windows 11 and Windows Server releases. Because CLFS is a core kernel component, a successful exploit can cross a security boundary and gain SYSTEM-level rights.
Description
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a local privilege escalation to SYSTEM with a KEV listing confirming in-the-wild exploitation, though it requires an existing foothold on the host.
What it is
CVE-2023-36424 is an out-of-bounds read (CWE-125) in the Windows Common Log File System (CLFS) driver that allows elevation of privilege. It affects a broad set of Windows 10, Windows 11 and Windows Server releases. Because CLFS is a core kernel component, a successful exploit can cross a security boundary and gain SYSTEM-level rights.
Impact
An attacker who already has a foothold on the host can elevate from a low-privileged account to SYSTEM, gaining full control of the machine. That enables credential theft, disabling of defenses and lateral movement.
Attack surface
The CVSS vector is local (AV:L), low complexity, low privileges required and no user interaction, so the flaw is reached by running code on the target host rather than over the network. No remote or unauthenticated path is described in the record.
Exploitation
CVE-2023-36424 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating exploitation in the wild, and its EPSS 30-day probability is about 12% (95.9th percentile). The record does not state which actors or campaigns use it, and no ransomware association is documented.
What to do
- Apply the Microsoft security update for CVE-2023-36424 on all affected Windows 10, Windows 11 and Windows Server builds; prioritize internet-facing and high-value hosts.
- Follow CISA KEV required action: apply vendor mitigations, apply BOD 22-01 guidance for cloud services, or discontinue use of the product if no mitigation exists.
- Restrict local interactive and service-account access so untrusted users cannot run code on sensitive hosts.
- Monitor for and block known CLFS exploitation tooling and suspicious driver interaction from non-administrative processes.
- Verify patch status across the full affected product list, including older Windows Server 2008/2012 builds that may be out of support.
Detection
- Alert on unexpected processes loading or opening CLFS log files and the clfs.sys driver from non-system contexts.
- Monitor for privilege escalation behavior: low-privileged processes spawning SYSTEM-level children or writing to protected paths.
- Hunt for known CLFS exploit artifacts and crash patterns in clfs.sys via endpoint telemetry and Windows Error Reporting.
- Correlate local logon and process creation events on hosts that have not yet been patched for this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-36424 to the Known Exploited Vulnerabilities catalog on 13 April 2026 as "Microsoft Windows Out-of-Bounds Read Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 27 April 2026.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36424 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36424 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-36424 | US Government Resource |
Track CVE-2023-36424 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-36424), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.