CVE-2023-28252
published 2023-04-11CVE-2023-28252: Windows Common Log File System Driver Elevation of Privilege Vulnerability
PriorityP188high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2023-05-02
Exploited in the wild
EPSS
48.97%
98.8th percentile
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19869 | 10.0.10240.19869 |
| microsoft | windows_10_1607 | < 10.0.14393.5850 | 10.0.14393.5850 |
| microsoft | windows_10_1809 | < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_10_20h2 | < 10.0.19042.2846 | 10.0.19042.2846 |
| microsoft | windows_10_21h2 | < 10.0.19044.2846 | 10.0.19044.2846 |
| microsoft | windows_10_22h2 | < 10.0.19045.2846 | 10.0.19045.2846 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19869 | 10.0.10240.19869 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5850 | 10.0.14393.5850 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.4252 | 10.0.17763.4252 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2846 | 10.0.19042.2846 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2846 | 10.0.19044.2846 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2846 | 10.0.19045.2846 |
| microsoft | windows_11_21h2 | < 10.0.22000.1817 | 10.0.22000.1817 |
| microsoft | windows_11_22h2 | < 10.0.22621.1555 | 10.0.22621.1555 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1817 | 10.0.22000.1817 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.1555 | 10.0.22621.1555 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26466 | 6.1.7601.26466 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.22015 | 6.0.6003.22015 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24216 | 6.2.9200.24216 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20919 | 6.3.9600.20919 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5850 | 10.0.14393.5850 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.4252 | 10.0.17763.4252 |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit artifact files dropped under C:\Users\Public\ — monitor for creation of .blf files and files matching p_* pattern in that directory ↗
- →The exploit triggers vulnerability via the AddLogContainer API call leading to CClfsBaseFilePersisted::ExtendMetadataBlock; monitor for unusual .blf file creation followed by AddLogContainer calls from non-system processes ↗
- →Exploit uses NtQuerySystemInformation with SystemExtendedHandleInformation (class 0x40) to leak kernel addresses; monitor for Medium IL processes calling NtQuerySystemInformation with class 0x40 ↗
- →CVE-2023-28252 exploit modifies LogBlockHeader->ValidSectorCount and fields in LogBlockHeader->Record[0] for both CONTROL and CONTROL_SHADOW metadata blocks in a .blf file; forensic analysis of .blf files for these field modifications can identify exploitation attempts ↗
- ·Microsoft does not document the .blf (base log file) format; the exploit manipulates undocumented kernel structures within .blf files. Exact field names and values that trigger CVE-2023-28252 were intentionally withheld by Kaspersky to allow patching time. ↗
- ·The vulnerability may be silently masked by exception handlers in clfs.sys, meaning crash-based fuzzing may not detect exploitation attempts — behavioral monitoring is required ↗
- ·The NtQuerySystemInformation kernel address leak technique used by the exploit requires Medium Integrity Level (Medium IL); it does not work from Low IL processes, limiting exploitation to already-elevated (at least medium IL) user contexts ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-385j-3gwh-pjgr: Windows Common Log File System Driver Elevation of Privilege Vulnerability
ghsa_unreviewed·2023-04-11
CVE-2023-28252 [HIGH] CWE-122 GHSA-385j-3gwh-pjgr: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
VulnCheck
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
vulncheck·2023·CVSS 7.8
CVE-2023-28252 [HIGH] CWE-122 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2023-Apr; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://decoded.avast.io/threatresearch/avast-q1-2023-threat-report/; https://securelist.com/it-threat-evolution-q2
Project0
Project Zero RCA: CVE-2023-28252: Windows Common Log File System Driver Elevation of Privilege Vulnerability
project_zero·CVSS 7.8
CVE-2023-28252 [HIGH] Project Zero RCA: CVE-2023-28252: Windows Common Log File System Driver Elevation of Privilege Vulnerability
# CVE-2023-28252: Windows Common Log File System Driver Elevation of Privilege Vulnerability
*Genwei Jiang, FLARE OTF*
## The Basics
**Disclosure or Patch Date:** April 11, 2023
**Product:** Windows
**Advisory:** https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-28252
**Affected Versions:** Before security updates of April 11, 2023, for Windows 10, 11 and Windows Server 2008, 2012, 2016, 2019, 2022
**First Patched Version:** Security updates of April 11, 2023, for CVE-2023-28252
**Issue/Bug Report:** MSRC-78564
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** Boris Larin (oct0xor) with Kaspersky, Genwei Jiang with FLARE OTF of Google Cloud + Mandiant, Quan Jin with DBAPPSecurity WeBin Lab
## The Code
**Proof-of-concept:** See exploit sample
**E
CISA
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
cisa·2023-04-11·CVSS 7.8
CVE-2023-28252 [HIGH] CWE-122 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-28252; https://nvd.nist.gov/vuln/detail/CVE-2023-28252
Remediation Due Date: 2023-05-02
Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability
vendor_msrc·2023-04-11·CVSS 7.8
CVE-2023-28252 [HIGH] CWE-122 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Common Log File System Driver: Windows Common Log File System Driver
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation Detected;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025229
Reference: https://support.microsoft.com/help/5025229
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025230
Reference: https://support.microsoft.com/help/502
No detection rules found.
Tenable
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
blogs_tenable·2026-05-27
CVE-2023-4966 Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploit
Bleepingcomputer
Microsoft: Windows CLFS zero-day exploited by ransomware gang
blogs_bleepingcomputer·2025-04-08·CVSS 7.8
[HIGH] Microsoft: Windows CLFS zero-day exploited by ransomware gang
## Microsoft: Windows CLFS zero-day exploited by ransomware gang
## Sergiu Gatlan
While the company has issued security updates for impacted Windows versions, it delayed releasing patches for systems running Windows 10 LTSB 2015 and said they would be released as soon as possible.
"The targets include organizations in the information technology (IT) and real estate sectors of the United States, the financial sector in Venezuela, a Spanish software company, and the retail sector in Saudi Arabia," Microsoft revealed today .
"Customers running Windows 11, version 24H2 are not affected by the observed exploitation, even if the vulnerability was present. Microsoft urges customers to apply these updates as soon as possible."
Microsoft linked these attacks to the RansomEXX ransomware gang, w
Bleepingcomputer
Microsoft patches Windows Kernel zero-day exploited since 2023
blogs_bleepingcomputer·2025-03-12·CVSS 7.8
CVE-2025-24983 [HIGH] Microsoft patches Windows Kernel zero-day exploited since 2023
## Microsoft patches Windows Kernel zero-day exploited since 2023
## Sergiu Gatlan
ESET said on Tuesday that a zero-day exploit targeting the CVE-2025-24983 vulnerability was "first seen in the wild" in March 2023 on systems backdoored using PipeMagic malware.
This exploit targets only older Windows versions (Windows Server 2012 R2 and Windows 8.1) that Microsoft no longer supports. However, the vulnerability also affects newer Windows versions, including the still-supported Windows Server 2016 and Windows 10 systems running Windows 10 build 1809 and earlier.
"The Use-After-Free (UAF) vulnerability is related to improper memory usage during software operation. This can lead to software crashes, execution of malicious code (including remotely), privilege escalation, or data corruption,"
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Tenable
Microsoft’s December 2024 Patch Tuesday Addresses 70 CVEs (CVE-2024-49138)
blogs_tenable·2024-12-10·CVSS 7.8
[HIGH] Microsoft’s December 2024 Patch Tuesday Addresses 70 CVEs (CVE-2024-49138)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Microsoft: Ransomware gangs exploit VMware ESXi auth bypass in attacks
blogs_bleepingcomputer·2024-07-29·CVSS 6.8
CVE-2024-37085 [MEDIUM] Microsoft: Ransomware gangs exploit VMware ESXi auth bypass in attacks
## Microsoft: Ransomware gangs exploit VMware ESXi auth bypass in attacks
## Sergiu Gatlan
Microsoft warned today that ransomware gangs are actively exploiting a VMware ESXi authentication bypass vulnerability in attacks.
Tracked as CVE-2024-37085 , this medium-severity security flaw was discovered by Microsoft security researchers Edan Zwick, Danielle Kuznets Nohi, and Meitar Pinto and fixed with the release of ESXi 8.0 U3 on June 25.
The bug enables attackers to add a new user to an 'ESX Admins' group they create, a user that will automatically be assigned full administrative privileges on the ESXi hypervisor.
"A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-cr
Sentinelone
Brain Cipher
blogs_sentinelone·2024-07-02
Brain Cipher
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Securelist
Exploits and vulnerabilities in Q1 2024
blogs_securelist·2024-05-07·CVSS 7.8
CVE-2024-3094 [HIGH] Exploits and vulnerabilities in Q1 2024
Table of Contents
Statistics on registered vulnerabilities
Exploitation statistics
Windows and Linux vulnerability exploitation
Public exploit statistics
Most prevalent exploits
Vulnerability exploitation in APT attacks
Notable Q1 2024 vulnerabilities
CVE-2024-3094 (XZ)
CVE-2024-20656 (Visual Studio)
CVE-2024-21626 (runc)
CVE-2024-1708 (ScreenConnect)
CVE-2024-21412 (Windows Defender)
CVE-2024-27198 (TeamCity)
CVE-2023-38831 (WinRAR)
Conclusions and advice
Authors
Alexander Kolesnikov
Vitaly Morgunov
We at Kaspersky continuously monitor the evolving cyberthreat landscape to ensure we respond promptly to emerging threats, equipping our products with detection logic and technology. Software vulnerabilities that threat actors can exploit or are already actively exploiting a
Securelist
Analyzing the vulnerability landscape in Q1 2024
blogs_securelist·2024-05-07
Analyzing the vulnerability landscape in Q1 2024
Table of Contents
- Statistics on registered vulnerabilities
- Exploitation statistics
- Vulnerability exploitation in APT attacks
- Notable Q1 2024 vulnerabilities
- Conclusions and advice
Authors
- Alexander Kolesnikov
- Vitaly Morgunov
We at Kaspersky continuously monitor the evolving cyberthreat landscape to ensure we respond promptly to emerging threats, equipping our products with detection logic and technology. Software vulnerabilities that threat actors can exploit or are already actively exploiting are a critical component of that landscape. In this report, we present a series of insightful statistical and analytical snapshots relating to the trends in the emergence of new vulnerabilities and exploits, as well as the most prevalent vulnerabilities being used by attackers. Add
Qualys
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk
blogs_qualys·2024-03-25
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk
## Table of Contents
Announcing MITRE ATT&CK Matrix Prioritization in Qualys VMDR
MITRE ATT&CK Framework
Top MITRE ATT&CK Tactics and Techniques Leveraged
How to Combine Qualys TruRisk and MITRE ATT&CK to Reduce Your Cyber Risk
Using the MITRE ATT&CK Matrix for Prioritization
Remediation Strategies
Conclusion
Contributors
There are so many vulnerabilities disclosed daily that no one can patch all of them. Unfortunately, attackers can exploit them while you are still in the process of reviewing, prioritizing, and patching. Effective risk-based prioritization focuses your limited resources and remediation efforts where you will have the greatest impact in reducing risk and safeguarding your assets.
While CVSS and EPSS are foundational metrics for risk severity, they can miss real t
Qualys
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk | Qualys
blogs_qualys·2024-03-25
Combine Qualys TruRisk™ and MITRE ATT&CK to Adopt Threat-Informed Defense to Reduce Risk | Qualys
#### Table of Contents
- Announcing MITRE ATT&CK Matrix Prioritization in Qualys VMDR
- MITRE ATT&CK Framework
- Top MITRE ATT&CK Tactics and Techniques Leveraged
- How to Combine Qualys TruRisk and MITRE ATT&CK to Reduce Your Cyber Risk
- Using the MITRE ATT&CK Matrix for Prioritization
- Remediation Strategies
- Conclusion
- Contributors
There are so many vulnerabilities disclosed daily that no one can patch all of them. Unfortunately, attackers can exploit them while you are still in the process of reviewing, prioritizing, and patching. Effective risk-based prioritization focuses your limited resources and remediation efforts where you will have the greatest impact in reducing risk and safeguarding your assets.
While CVSS and EPSS are foundational metrics for risk severity, they can
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #1 – CVE-2022-24521)
blogs_securelist·2023-12-21·CVSS 7.8
[HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #1 – CVE-2022-24521)
Authors
Boris Larin
This is the second part of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous part first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
Part 1 – Windows CLFS and five exploits of ransomware operators
Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
Part 5 – Windows CLFS and five exploits of ransomware operators (Explo
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #3 – October 2022)
blogs_securelist·2023-12-21·CVSS 7.8
[HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #3 – October 2022)
Authors
- Boris Larin
This is part four of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
- Part 1 – Windows CLFS and five exploits of ransomware operators
- Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
- Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
- Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
- Part 5 – Windows CLFS and five exploits of ransomware operators (Ex
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #4 – CVE-2023-23376)
blogs_securelist·2023-12-21·CVSS 7.8
[HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #4 – CVE-2023-23376)
Authors
Boris Larin
This is part five of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
Part 1 – Windows CLFS and five exploits of ransomware operators
Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
Part 5 – Windows CLFS and five exploits of ransomware operators (Exploit #4
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #2 – September 2022)
blogs_securelist·2023-12-21·CVSS 7.8
[HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #2 – September 2022)
Authors
Boris Larin
This is the third part of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
Part 1 – Windows CLFS and five exploits of ransomware operators
Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
Part 5 – Windows CLFS and five exploits of ransomware operators (Explo
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #4 – CVE-2023-23376)
blogs_securelist·2023-12-21·CVSS 7.8
CVE-2023-23376 [HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #4 – CVE-2023-23376)
Authors
- Boris Larin
This is part five of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
- Part 1 – Windows CLFS and five exploits of ransomware operators
- Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
- Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
- Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
- Part 5 – Windows CLFS and five exploits of ransomware operators (Ex
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #2 – September 2022)
blogs_securelist·2023-12-21·CVSS 7.8
[HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #2 – September 2022)
Authors
- Boris Larin
This is the third part of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
- Part 1 – Windows CLFS and five exploits of ransomware operators
- Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
- Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
- Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
- Part 5 – Windows CLFS and five exploits of ransomware operator
Securelist
Windows CLFS and five exploits used by ransomware operators
blogs_securelist·2023-12-21·CVSS 7.8
CVE-2023-28252 [HIGH] Windows CLFS and five exploits used by ransomware operators
Authors
- Boris Larin
In April 2023, we published a blog post about a zero-day exploit we discovered in ransomware attacks that was patched as CVE-2023-28252 after we promptly reported it to Microsoft.
In that blog post, we mentioned that the zero-day exploit we discovered was very similar to other Microsoft Windows elevation-of-privilege (EoP) exploits that we have seen in ransomware attacks throughout the year. We found that since June 2022, attackers have used exploits for at least five different Common Log File System (CLFS) driver vulnerabilities. Four of these vulnerabilities used by the attackers (CVE-2022-24521, CVE-2022-37969, CVE-2023-23376, CVE-2023-28252) have been captured in the wild as zero-days.
Seeing a Win32k driver zero-day being used in attacks isn’t really surprisi
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #3 – October 2022)
blogs_securelist·2023-12-21·CVSS 7.8
[HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #3 – October 2022)
Authors
Boris Larin
This is part four of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
Part 1 – Windows CLFS and five exploits of ransomware operators
Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
Part 5 – Windows CLFS and five exploits of ransomware operators (Exploit #4
Securelist
Windows CLFS and five exploits used by ransomware operators
blogs_securelist·2023-12-21·CVSS 7.8
CVE-2023-28252 [HIGH] Windows CLFS and five exploits used by ransomware operators
Authors
Boris Larin
In April 2023, we published a blog post about a zero-day exploit we discovered in ransomware attacks that was patched as CVE-2023-28252 after we promptly reported it to Microsoft.
In that blog post, we mentioned that the zero-day exploit we discovered was very similar to other Microsoft Windows elevation-of-privilege (EoP) exploits that we have seen in ransomware attacks throughout the year. We found that since June 2022, attackers have used exploits for at least five different Common Log File System (CLFS) driver vulnerabilities. Four of these vulnerabilities used by the attackers ( CVE-2022-24521 , CVE-2022-37969 , CVE-2023-23376 , CVE-2023-28252 ) have been captured in the wild as zero-days.
Seeing a Win32k driver zero-day being used in attacks isn’t really surpr
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #1 – CVE-2022-24521)
blogs_securelist·2023-12-21·CVSS 7.8
CVE-2022-24521 [HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #1 – CVE-2022-24521)
Authors
- Boris Larin
This is the second part of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous part first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
- Part 1 – Windows CLFS and five exploits of ransomware operators
- Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
- Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
- Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
- Part 5 – Windows CLFS and five exploits of ransomware operator
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #5 – CVE-2023-28252)
blogs_securelist·2023-12-21·CVSS 7.8
CVE-2022-24521 [HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #5 – CVE-2023-28252)
Authors
Boris Larin
This is part six of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can go to other parts using this table of contents:
Part 1 – Windows CLFS and five exploits of ransomware operators
Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
Part 5 – Windows CLFS and five exploits of ransomware operators (Exploit #4 – CVE-2023-23376)
Part 6 – Windows CLFS and fiv
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #5 – CVE-2023-28252)
blogs_securelist·2023-12-21·CVSS 7.8
CVE-2023-28252 [HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #5 – CVE-2023-28252)
Authors
- Boris Larin
This is part six of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can go to other parts using this table of contents:
- Part 1 – Windows CLFS and five exploits of ransomware operators
- Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
- Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
- Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
- Part 5 – Windows CLFS and five exploits of ransomware operators (Exploit #4 – CVE-2023-23376)
- Part 6 – Windows CLF
Qualys
2023 Threat Landscape Year in Review: If Everything Is Critical, Nothing Is
blogs_qualys·2023-12-19
2023 Threat Landscape Year in Review: If Everything Is Critical, Nothing Is
## Table of Contents
2023 Statistics
2023 Vulnerability Threat Landscape
Top Vulnerability Types
Key Insights
Top MITRE ATT&CK Tactics & Techniques
Most Active Threats
Conclusion
As 2023 nears its end, it’s time to pause and reflect. It’s time to assess what worked and what didn’t, what caught our attention and caused disruption, and what went unnoticed. More importantly, we need to know what lessons we learned from 2023 so that we can do a better job of managing risk in the coming year. In line with this, the Qualys Threat Research Unit has prepared a comprehensive blog series to review the threat landscape in 2023.
Key Takeaways:
Less than one percent of vulnerabilities contributed to the highest risk and were routinely exploited in the wild.
97 high-risk vulnerabilities, like
Qualys
Top Cyber Threats of 2023: An In-Depth Review (Part One) | Qualys
blogs_qualys·2023-12-19
Top Cyber Threats of 2023: An In-Depth Review (Part One) | Qualys
#### Table of Contents
- 2023 Statistics
- 2023 Vulnerability Threat Landscape
- Top Vulnerability Types
- Key Insights
- Top MITRE ATT&CK Tactics & Techniques
- Most Active Threats
- Conclusion
As 2023 nears its end, it’s time to pause and reflect. It’s time to assess what worked and what didn’t, what caught our attention and caused disruption, and what went unnoticed. More importantly, we need to know what lessons we learned from 2023 so that we can do a better job of managing risk in the coming year. In line with this, the Qualys Threat Research Unit has prepared a comprehensive blog series to review the threat landscape in 2023.
Key Takeaways:
- Less than one percent of vulnerabilities contributed to the highest risk and were routinely exploited in the wild.
- 97 high-risk vulnerab
Tenable
Microsoft Patch Tuesday 2023 Year in Review
blogs_tenable·2023-12-12
Microsoft Patch Tuesday 2023 Year in Review
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s November 2023 Patch Tuesday Addresses 57 CVEs (CVE-2023-36025)
blogs_tenable·2023-11-14·CVSS 8.8
[HIGH] Microsoft’s November 2023 Patch Tuesday Addresses 57 CVEs (CVE-2023-36025)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Top 10 Exploited Vulnerabilities in 2023: Insights from the Qualys Survey | Qualys
blogs_qualys·2023-09-26·CVSS 7.8
[HIGH] Top 10 Exploited Vulnerabilities in 2023: Insights from the Qualys Survey | Qualys
#### Table of Contents
- 7 Key Insights by the Qualys Threat Research Unit
- A Closer Look at the Top 10 Exploited Vulnerabilities of 2023
- Optimizing Risk Management with Qualys VMDR TruRiskDashboard
- Next Steps: Reduce Your Risk to the Top 10 Vulnerabilities with Qualys VMDR
- Additional Contributors:
The Qualys Threat Research Unit (TRU) has thoroughly analyzed vulnerabilities reported in 2023. Our comprehensive study assesses factors including weaponization status, existence in the CISA KEV, instances or usage of malware and ransomware, trending vulnerabilities, various scoring metrics, and recency of threats. Insights for the Top 10 vulnerabilities during 2023 are also based on evidence of exploitation, patch adoption rates, and the longevity of vulnerabilities.
## 7 Key Insights
Qualys
Qualys Survey of Top 10 Exploited Vulnerabilities in 2023
blogs_qualys·2023-09-26·CVSS 7.8
[HIGH] Qualys Survey of Top 10 Exploited Vulnerabilities in 2023
## Table of Contents
7 Key Insights by the Qualys Threat Research Unit
A Closer Look at the Top 10 Exploited Vulnerabilities of 2023
Optimizing Risk Management with Qualys VMDR TruRiskDashboard
Next Steps: Reduce Your Risk to the Top 10 Vulnerabilities with Qualys VMDR
Additional Contributors:
The Qualys Threat Research Unit (TRU) has thoroughly analyzed vulnerabilities reported in 2023. Our comprehensive study assesses factors including weaponization status, existence in the CISA KEV, instances or usage of malware and ransomware, trending vulnerabilities, various scoring metrics, and recency of threats. Insights for the Top 10 vulnerabilities during 2023 are also based on evidence of exploitation, patch adoption rates, and the longevity of vulnerabilities.
## 7 Key Insights by the
Tenable
Microsoft’s September 2023 Patch Tuesday Addresses 61 CVEs (CVE-2023-36761)
blogs_tenable·2023-09-12·CVSS 6.5
[MEDIUM] Microsoft’s September 2023 Patch Tuesday Addresses 61 CVEs (CVE-2023-36761)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
IT threat evolution in Q2 2023. Non-mobile statistics
blogs_securelist·2023-08-30
IT threat evolution in Q2 2023. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
MOVEit Transfer vulnerabilities exploited
Attacks on municipal organizations, educational and healthcare establishments
Most prolific groups
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks on IoT
Securelist
IT threat evolution Q2 2023
blogs_securelist·2023-08-30
IT threat evolution Q2 2023
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
- IT threat evolution in Q2 2023
- IT threat evolution in Q2 2023. Non-mobile statistics
- IT threat evolution in Q2 2023. Mobile statistics
## Targeted attacks
### Gopuram backdoor deployed through 3CX supply-chain attack
Earlier this year, a Trojanized version of the 3CXDesktopApp, a popular VoIP program, was used in a high-supply-chain attack. The attackers were able to embed malicious code into the libffmpeg media processing library to download a payload from their servers.
When we reviewed our telemetry on the campaign, we found a DLL on one of the computers, named guard64.dll, which was loaded into the infected 3CXDesktopApp.exe process. A DLL with this name was used in recent deployments of a backdoor t
Securelist
PC malware statistics, Q2 2022
blogs_securelist·2023-08-30
PC malware statistics, Q2 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Most prolific groups
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks on IoT honeypots
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q2 2023
- IT threat evolution in Q2 2023. Non-mobile statistics
- IT threat evolution in Q2 2023. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q2 2023:
- Kaspersky solutions blocked 801,934,281 attacks from online resources across the globe.
- A total of 209,716,810 unique links were d
Tenable
Microsoft’s August 2023 Patch Tuesday Addresses 73 CVEs (CVE-2023-38180)
blogs_tenable·2023-08-08·CVSS 7.5
[HIGH] Microsoft’s August 2023 Patch Tuesday Addresses 73 CVEs (CVE-2023-38180)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Wiz
Crying Out Cloud - April Newsletter | Wiz
blogs_wiz·2023-05-01·CVSS 7.8
[HIGH] Crying Out Cloud - April Newsletter | Wiz
Cloud security is constantly evolving, and the Wiz Research team is dedicated to keeping you informed. The past month has seen significant vulnerabilities discovered, and there have been a few security incidents affecting cloud users.
We've compiled a shortlist of the most relevant developments. Here are our top picks!
## ✨ Highlights
## BrokenSesame : Accidental ‘write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services
Wiz Research has discovered a chain of critical vulnerabilities in two of Alibaba Cloud׳s popular services, AsparaDB RDS for PostrgreSQL and AnalyticDB for PostgreSQL. Dubbed "BrokenSesame", the vulnerabilities allowed unauthorized cross-tenant access to other customers` PostgreSQL databases and the ability to perform a supply-chai
Checkpoint
17th April – Threat Intelligence Report
blogs_checkpoint·2023-04-17
CVE-2023-28302 17th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th April, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
Two major automotive manufacturers Hyundai and Toyota have disclosed significant data breaches. Hyundai’s Italian and French car owners were affected, along with individuals who booked a test drive. The leaked data consists of clients’ personal information including emails, addresses, phone numbers, and vehicle chassis numbers.
Wiz
Microsoft April 2023 Patch Tuesday Highlights: everything you need to know | Wiz Blog
blogs_wiz·2023-04-13·CVSS 9.8
CVE-2023-28252 [CRITICAL] Microsoft April 2023 Patch Tuesday Highlights: everything you need to know | Wiz Blog
Among the 97 vulnerabilities patched by Microsoft this Patch Tuesday, two vulnerabilities caught our attention. Learn how to detect and mitigate CVE-2023-28252, an elevation of privilege (EoP) vulnerability in CLFS exploited in the wild, and CVE-2023-21554, a critical remote code execution (RCE) vulnerability in MSMQ.
# What is CVE-2023-21554?
Researchers published CVE-2023-21554, a critical RCE vulnerability in “Microsoft Message Queuing” service, also known as MSMQ. The vulnerability allows unauthenticated attackers to execute arbitrary code in the context of the Windows service process, `mqsvc.exe`. It was patched on April 11 as part of April Patch Tuesday, and dubbed QueueJumper.
MSMQ is a messaging platform and development framework that enables the creation of distributed messagin
Talos
Threat Source newsletter (April 13, 2023) — Dark web forum whac-a-mole
blogs_talos·2023-04-13
Threat Source newsletter (April 13, 2023) — Dark web forum whac-a-mole
Welcome to this week’s edition of the Threat Source newsletter.
Law enforcement organizations across the globe notched a series of wins over the past few weeks against online forums for cybercriminals.
On March 23, the FBI announced it disrupted the online cybercriminal marketplace BreachForums, known for being a place where users could buy and sell stolen user information. They also arrested a 20-year-old suspected of being the site’s founder and main administrator.
Then last week we had “Operation Cookie Monster” in which several international agencies worked together to take down Genesis Market, a similar dark web forum, arresting dozens of suspected users and administrators.
These arrests and network operations are important in that they disrupted sites that were known for highly s
Wiz
Microsoft April 2023 Patch Tuesday Highlights: everything you need to know | Wiz Blog
blogs_wiz·2023-04-13·CVSS 9.8
CVE-2023-28252 [CRITICAL] Microsoft April 2023 Patch Tuesday Highlights: everything you need to know | Wiz Blog
Among the 97 vulnerabilities patched by Microsoft this Patch Tuesday, two vulnerabilities caught our attention. Learn how to detect and mitigate CVE-2023-28252, an elevation of privilege (EoP) vulnerability in CLFS exploited in the wild, and CVE-2023-21554, a critical remote code execution (RCE) vulnerability in MSMQ.
## What is CVE-2023-21554?
Researchers published CVE-2023-21554, a critical RCE vulnerability in “Microsoft Message Queuing” service, also known as MSMQ. The vulnerability allows unauthenticated attackers to execute arbitrary code in the context of the Windows service process, `mqsvc.exe`. It was patched on April 11 as part of April Patch Tuesday, and dubbed QueueJumper.
MSMQ is a messaging platform and development framework that enables the creation of distributed messagi
Talos
Threat Source newsletter (April 13, 2023) — Dark web forum whac-a-mole
blogs_talos·2023-04-13
Threat Source newsletter (April 13, 2023) — Dark web forum whac-a-mole
## Threat Source newsletter (April 13, 2023) — Dark web forum whac-a-mole
Welcome to this week’s edition of the Threat Source newsletter.
Law enforcement organizations across the globe notched a series of wins over the past few weeks against online forums for cybercriminals.
On March 23, the FBI announced it disrupted the online cybercriminal marketplace BreachForums , known for being a place where users could buy and sell stolen user information. They also arrested a 20-year-old suspected of being the site’s founder and main administrator.
Then last week we had “Operation Cookie Monster” in which several international agencies worked together to take down Genesis Market , a similar dark web forum, arresting dozens of suspected users and administrators.
These arrests and network opera
Qualys
Microsoft and Adobe Patch Tuesday April 2023 Security Update Review | Qualys
blogs_qualys·2023-04-12
Microsoft and Adobe Patch Tuesday April 2023 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for April 2023
- Adobe Patches for April 2023
- Zero-day Vulnerability Patched in April Patch Tuesday Edition
- Other Critical Severity Vulnerabilities Patched in April Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
- Qualys Monthly Webinar Series
- This Month in Vulnerabilities & Patches
Microsoft released security updates to address 114 vulnerabilities in the April Patch Tuesday edition. The security advisories co
Krebs
Microsoft (& Apple) Patch Tuesday, April 2023 Edition
blogs_krebs·2023-04-12·CVSS 8.8
CVE-2023-28206 [HIGH] Microsoft (& Apple) Patch Tuesday, April 2023 Edition
Microsoft today released software updates to plug 100 security holes in its Windows operating systems and other software, including a zero-day vulnerability that is already being used in active attacks. Not to be outdone, Apple has released a set of important updates addressing two zero-day vulnerabilities that are being used to attack iPhones , iPads and Macs .
On April 7, Apple issued emergency security updates to fix two weaknesses that are being actively exploited, including CVE-2023-28206 , which can be exploited by apps to seize control over a device. CVE-2023-28205 can be used by a malicious or hacked website to install code.
Both vulnerabilities are addressed in iOS/iPadOS 16.4.1, iOS 15.7.5, and macOS 12.6.5 and 11.7.6 . If you use Apple devices and you don’t have automatic upda
Qualys
Microsoft and Adobe Patch Tuesday April 2023 Security Update Review
blogs_qualys·2023-04-12
Microsoft and Adobe Patch Tuesday April 2023 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for April 2023
Adobe Patches for April 2023
Zero-day Vulnerability Patched in April Patch Tuesday Edition
Other Critical Severity Vulnerabilities Patched in April Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
Qualys Monthly Webinar Series
This Month in Vulnerabilities & Patches
Microsoft released security updates to address 114 vulnerabilities in the April Patch Tuesday edition. The security advisories cover various vul
Securelist
Nokoyawa ransomware attacks with Windows zero-day
blogs_securelist·2023-04-11·CVSS 7.8
[HIGH] Nokoyawa ransomware attacks with Windows zero-day
Table of Contents
- Elevation-of-privilege exploit
- Post exploitation and malware
- Conclusions
- Indicators of compromise
Authors
- Boris Larin
Updated April 20, 2023
In February 2023, Kaspersky technologies detected a number of attempts to execute similar elevation-of-privilege exploits on Microsoft Windows servers belonging to small and medium-sized businesses in the Middle East, in North America, and previously in Asia regions. These exploits were very similar to already known Common Log File System (CLFS) driver exploits that we analyzed previously, but we decided to double check and it was worth it – one of the exploits turned out to be a zero-day, supporting different versions and builds of Windows, including Windows 11. The exploit was highly obfuscated with more than 80% of
Talos
Microsoft Patch Tuesday for April 2023 — Snort rules and prominent vulnerabilities
blogs_talos·2023-04-11·CVSS 7.8
CVE-2023-28252 [HIGH] Microsoft Patch Tuesday for April 2023 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for April 2023 — Snort rules and prominent vulnerabilities
Microsoft released its monthly round of security updates and patches today, continuing its trend of fixing zero-day vulnerabilities on Patch Tuesday.
April's security update includes one vulnerability that’s actively being exploited in the wild. There are also eight critical vulnerabilities and the remaining 90 are considered “important.”
CVE-2023-28252 , an elevation of privilege vulnerability in the Windows Common Log File System Driver, is actively being exploited in the wild, according to Microsoft, though proof of concept code is not currently available. An adversary could exploit this vulnerability to gain SYSTEM privileges.
The U.S. Cybersecurity and Infrastructure Security Agency already added
Talos
Microsoft Patch Tuesday for April 2023 — Snort rules and prominent vulnerabilities
blogs_talos·2023-04-11·CVSS 7.8
CVE-2023-28252 [HIGH] Microsoft Patch Tuesday for April 2023 — Snort rules and prominent vulnerabilities
Microsoft released its monthly round of security updates and patches today, continuing its trend of fixing zero-day vulnerabilities on Patch Tuesday.
April's security update includes one vulnerability that’s actively being exploited in the wild. There are also eight critical vulnerabilities and the remaining 90 are considered “important.”
CVE-2023-28252, an elevation of privilege vulnerability in the Windows Common Log File System Driver, is actively being exploited in the wild, according to Microsoft, though proof of concept code is not currently available. An adversary could exploit this vulnerability to gain SYSTEM privileges.
The U.S. Cybersecurity and Infrastructure Security Agency already added the vulnerability to its list of know exploited issues and urged federal agencies to pa
Tenable
Microsoft’s April 2023 Patch Tuesday Addresses 97 CVEs (CVE-2023-28252)
blogs_tenable·2023-04-11·CVSS 7.8
[HIGH] Microsoft’s April 2023 Patch Tuesday Addresses 97 CVEs (CVE-2023-28252)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
Nokoyawa ransomware attacks with Windows zero-day
blogs_securelist·2023-04-11·CVSS 7.8
[HIGH] Nokoyawa ransomware attacks with Windows zero-day
Table of Contents
Elevation-of-privilege exploit
Post exploitation and malware
Conclusions
Indicators of compromise
Authors
Boris Larin
Updated April 20, 2023
In February 2023, Kaspersky technologies detected a number of attempts to execute similar elevation-of-privilege exploits on Microsoft Windows servers belonging to small and medium-sized businesses in the Middle East, in North America, and previously in Asia regions. These exploits were very similar to already known Common Log File System (CLFS) driver exploits that we analyzed previously, but we decided to double check and it was worth it – one of the exploits turned out to be a zero-day, supporting different versions and builds of Windows, including Windows 11. The exploit was highly obfuscated with more than 80% of the its
Krebs
Microsoft (& Apple) Patch Tuesday, April 2023 Edition
blogs_krebs·2023-04-11·CVSS 8.8
CVE-2023-28206 [HIGH] Microsoft (& Apple) Patch Tuesday, April 2023 Edition
Microsoft today released software updates to plug 100 security holes in its Windows operating systems and other software, including a zero-day vulnerability that is already being used in active attacks. Not to be outdone, Apple has released a set of important updates addressing two zero-day vulnerabilities that are being used to attack iPhones, iPads and Macs.
On April 7, Apple issued emergency security updates to fix two weaknesses that are being actively exploited, including CVE-2023-28206, which can be exploited by apps to seize control over a device. CVE-2023-28205 can be used by a malicious or hacked website to install code.
Both vulnerabilities are addressed in iOS/iPadOS 16.4.1, iOS 15.7.5, and macOS 12.6.5 and 11.7.6. If you use Apple devices and you don’t have automatic updates
Crowdstrike
April 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] April 2023 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Sentinelone
Brain Cipher
blogs_sentinelone·CVSS 7.8
[HIGH] Brain Cipher
# Brain Cipher Ransomware: In-Depth Analysis, Detection, and Mitigation
## What Is Brain Cipher Ransomware?
Brain Cipher Ransomware emerged in early June 2024. The group engages in multi-pronged extortion, hosting a TOR-based data leak site. The threat actor’s payloads are based on LockBit 3.0.
## What Does Brain Cipher Ransomware Target?
Brain Cipher operators have targeted multiple critical industries, including medical, educational, and manufacturing entities. The group is also known to attack government and law enforcement targets, a previous target having been Indonesia’s National Data Center. This particular attack caused significant disruptions to public services, including immigration and new student registration systems.
## How Does Brain Cipher Ransomware Work?
Initial acce
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252http://packetstormsecurity.com/files/174668/Windows-Common-Log-File-System-Driver-clfs.sys-Privilege-Escalation.htmlhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28252
2023-04-11
Published
2023-04-11
Added to CISA KEV
Exploited in the wild