Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published: 2023-04-11
Microsoft addresses 97 CVEs, including one that was exploited in the wild as a zero day.
https://thehackernews.com/2025/04/pipemagic-trojan-exploits-windows-clfs.html
https://securelist.com/vulnerability-report-q1-2024/112554/
https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf
https://securelist.com/windows-clfs-exploits-ransomware/111560/
https://www.tenable.com/blog/microsofts-december-2024-patch-tuesday-addresses-70-cves-cve-2024-49138
https://www.tenable.com/blog/microsoft-patch-tuesday-2023-year-in-review
https://www.tenable.com/blog/microsofts-november-2023-patch-tuesday-addresses-57-cves-cve-2023-36025
https://www.tenable.com/blog/microsofts-august-2023-patch-tuesday-addresses-73-cves-cve-2023-38180
https://www.tenable.com/blog/microsofts-april-2023-patch-tuesday-addresses-97-cves-cve-2023-28252
Published: 2023-04-11
Updated: 2025-03-10
Named Vulnerability: Windows CLFS DriverKnown Exploited Vulnerability (KEV)
Base Score: 6.8
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C
Severity: Medium
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.58152