CVE-2023-28252 — Windows Common Log File System Driver Elevation of Privilege Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5025234 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 for x64-based Systems | 5025234 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5025228 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5025228 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5025229 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 5025229 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5025229 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 20H2 for 32-bit Systems | 5025221 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 20H2 for ARM64-based Systems | 5025221 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5025221 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5025221 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5025221 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5025221 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5025221 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5025221 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for ARM64-based Systems | 5025224 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 21H2 for x64-based Systems | 5025224 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5025239 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5025239 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 5025271 (Monthly Rollup) 5025273 (Security Only) Important Elevation of Privilege 5023755 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5025271 (Monthly Rollup) 5025273 (Security Only) Important Elevation of Privilege 5023755 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 for x64-based Systems Service Pack 2 5025271 (Monthly Rollup) 5025273 (Security Only) Important Elevation of Privilege 5023755 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5025271 (Monthly Rollup) 5025273 (Security Only) Important Elevation of Privilege 5023755 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.22015 Yes 5025271 5025273 Windows Server 2008 R2 for x64-based Systems Service Pack 1 5025279 (Monthly Rollup) 5025277 (Security Only) Important Elevation of Privilege 5023769 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.26466 Yes 5025279 5025277 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5025279 (Monthly Rollup) 5025277 (Security Only) Important Elevation of Privilege 5023769 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.26466 Yes 5025279 5025277 Windows Server 2012 5025287 (Monthly Rollup) 5025272 (Security Only) Important Elevation of Privilege 5023769 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.2.9200.24216 Yes None Windows Server 2012 (Server Core installation) 5025287 (Monthly Rollup) 5025272 (Security Only) Important Elevation of Privilege 5023769 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.2.9200.24216 Yes None Windows Server 2012 R2 5025285 (Monthly Rollup) 5025288 (Security Only) Important Elevation of Privilege 5023765 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.3.9600.20919 Yes None Windows Server 2012 R2 (Server Core installation) 5025285 (Monthly Rollup) 5025288 (Security Only) Important Elevation of Privilege 5023765 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.3.9600.20919 Yes None Windows Server 2016 | 5025228 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5025228 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5025229 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5025229 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 | 5025230 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 (Server Core installation) | 5025230 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5025234 |
Security Update | Yes |
5025228 |
Security Update | Yes |
5025229 |
Security Update | Yes |
5025221 |
Security Update | Yes |
5025224 |
Security Update | Yes |
5025239 |
Security Update | Yes |
5025230 |
Security Update | Yes |
Patch Diff
OOB read/write via iExtendBlock/iFlushBlock=0x13 in BLF control record. ExtendMetadataBlock and WriteMetadataBlock use these as array indices without bounds check. OOB write gives 1-byte increment primitive → CONTAINER_CONTEXT redirect → vtable hijack at 0x5000000. Fix: broad BLF validation in GetControlRecord (3x growth) + WriteMetadataBlock encode check + ValidateScratchBlockOffsets (2x growth). Gated on g_signatureOffsetsValidation. Exploited ITW by Nokoyawa ransomware.
| Function | Address | Change | Note |
|---|---|---|---|
CClfsBaseFile::GetControlRecord |
|
code, length, address, called | 3x growth (299→891 bytes). Validates iExtendBlock/iFlushBlock must be 2-3, block descriptor monotonicity, sector size consistency |
CClfsBaseFilePersisted::WriteMetadataBlock |
|
code, length, address, called | ClfsEncodeBlock return value now checked; write skipped on encode failure; conditional decode in cleanup |
CClfsBaseFile::ValidateScratchBlockOffsets |
|
code, fullname, length, sig, address, called | 2x growth (743→1519 bytes). Moved to CClfsLogFcbPhysical::. Reads scratch block from disk and validates sector counts, owner page offsets, monotonicity |
CClfsBaseFile::AcquireMetadataBlock |
|
code, length, address, called, calling | Null pointer check after metadata block acquisition; new caller ValidateScratchBlockOffsets |
CClfsLogFcbPhysical::AppendRegion |
|
code, length, address | Significant restructuring for bounds checking |
ClfsDecodeBlockPrivate |
|
code, length, address | Sector signature validation during decode |
Attack Path
Local EoP to SYSTEM via unvalidated rgBlocks[] indices in a crafted CLFS base log file - exploited in the wild by Nokoyawa ransomware
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
7 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| fortra/CVE-2023-28252 | 183 | 2023-06-27 | |
| duck-sec/CVE-2023-28252-Compiled-exe | 57 | 2024-01-22 | A modification to fortra's CVE-2023-28252 exploit, compiled to exe |
| byt3n33dl3/CLFS | 6 | 2024-03-21 | it's a CVE-2023-28252 (Patched), but feel free to use it for check any outdated software or reseach |
| bkstephen/Compiled-PoC-Binary-For-CVE-2023-28252 | 4 | 2024-01-01 | The repo contains a precompiled binary which can be run on a Windows machine vulnerable to CVE-2023-28252 |
| 726232111/CVE-2023-28252 | 0 | 2023-08-02 | |
| Danasuley/CVE-2023-28252- | 0 | 2023-11-13 | Обнаружение эксплойта CVE-2023-28252 |
| Vulmatch/CVE-2023-28252 | 0 | 2024-06-16 | The TL;DR for the learnings of Windows Vulnerability CVE-2023-28252 |
Detection Rules
Acknowledgments
Boris Larin (oct0xor)
Quan Jin with DBAPPSecurity WeBin Lab
Genwei Jiang with Mandiant