CVE detail
CVE-2023-23376
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
Microsoft has released a patch for a Windows zero day vulnerability that has been exploited by cybercriminals in ransomware attacks. The vulnerability, identified as CVE-2023-28252, is a privilege escalation flaw affecting the Windows Common Log File System (CLFS) driver. CLFS is a general purpose logging service that can be used by dedicated client applications and that […]
newswww.csoonline.comApr 13, 2023, 12:47 PM- Microsoft patches zero-day exploited by attackers (CVE-2023-28252)Help Net Security
It’s April 2023 Patch Tuesday, and Microsoft has released fixes for 97 CVE-numbered vulnerabilities, including one actively exploited zero-day (CVE-2023-28252). About CVE-2023-28252 CVE-2023-28252 is a vulnerability in the Windows Common Log File System (CLFS) that allows attackers to gain SYSTEM privileges on target machines. “Over the last two years, attackers appear to have found success targeting CLFS in order to elevate privileges as part of post-compromise activity,” Satnam Narang, senior staff research engineer at Tenable, … More →
newswww.helpnetsecurity.comApr 11, 2023, 7:11 PM - 20th February – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 20th February, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES Check Point Research identified a campaign against entities in Armenia, using a new version of OxtaRAT – an AutoIt-based backdoor for remote access and desktop surveillance. The threat actors have been targeting human […]
vendorresearch.checkpoint.comFeb 20, 2023, 4:33 PM - Week in review: Microsoft, Apple patch exploited zero-days, tips for getting hired in cybersecurityHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Combining identity and security strategies to mitigate risks The Identity Defined Security Alliance (IDSA), a nonprofit that provides vendor-neutral resources to help organizations reduce the risk of a breach by combining identity and security strategies, announced Jeff Reich as the organization’s new Executive Director. Can we predict cyber attacks? Bfore.AI says they can In this Help Net Security interview, Luigi … More →
newswww.helpnetsecurity.comFeb 19, 2023, 9:03 AM - CISA adds Cacti, Office, Windows and iOS bugs to its Known Exploited Vulnerabilities CatalogSecurity Affairs
US CISA added actively exploited flaws in Cacti framework, Microsoft Office, Windows, and iOS to its Known Exploited Vulnerabilities Catalog. US CISA added the following actively exploited flaws to its Known Exploited Vulnerabilities Catalog: CVE-2022-46169 – Cacti is an open-source platform that provides a robust and extensible operational monitoring and fault management framework for users. The flaw […]
newssecurityaffairs.comFeb 17, 2023, 5:40 AM No excerpt available.
Mitigationwww.cisa.govFeb 14, 2023, 8:15 PM- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23376msrc.microsoft.com
No excerpt available.
Vendor Advisorymsrc.microsoft.comFeb 14, 2023, 8:15 PM Microsoft Patch Tuesday security updates for February 2023 addressed 75 flaws, including three actively exploited zero-day bugs. Microsoft Patch Tuesday security updates for February 2023 fixed 75 vulnerabilities in multiple products, including Microsoft Windows and Windows Components; Office and Office Components; Exchange Server; .NET Core and Visual Studio Code; 3D Builder and Print 3D; Microsoft […]
newssecurityaffairs.comFeb 14, 2023, 8:11 PM- Microsoft patches three exploited zero-days (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823)Help Net Security
The February 2023 Patch Tuesday is upon us, with Microsoft releasing patches for 75 CVE-numbered vulnerabilities, including three actively exploited zero-day flaws (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823). The three zero-days (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823) CVE-2023-21715 a vulnerability that allows attackers to bypass a Microsoft Publisher security feature: Office macro policies used to block untrusted or malicious files. “The attack itself is carried out locally by a user with authentication to the targeted system. An authenticated attacker could exploit … More →
newswww.helpnetsecurity.comFeb 14, 2023, 7:28 PM Microsoft’s Patch Tuesday machine is humming loudly with software updates to fix at least 76 vulnerabilities in Windows and OS components.
newswww.securityweek.comFeb 14, 2023, 6:38 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-28252CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2024-38060CVSS 8.8 · High
Windows Imaging Component Remote Code Execution Vulnerability
- CVE-2024-38054CVSS 7.8 · High
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
- CVE-2024-38051CVSS 7.8 · High
Windows Graphics Component Remote Code Execution Vulnerability
- CVE-2024-38025CVSS 7.2 · High
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
- CVE-2024-30095CVSS 7.8 · High
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability