CVE-2023-23376

unknown KEV
Published 2023-02-14 ยท Modified 2023-02-14
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
1.5

Description

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

CISA KEV

Vendor
Microsoft
Product
Windows
Due date
2023-03-07

Predictions

Exploit likelihood
99%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Microsoft Security Response Center ยท View original โ†— ยท proprietary-no-redistribution
Full prose not cached โ€” VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftWindows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
microsoftWindows Server 2008 R2 for x64-based Systems Service Pack 1
microsoftWindows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
microsoftWindows Server 2012
microsoftWindows Server 2012 (Server Core installation)
microsoftWindows Server 2012 R2
microsoftWindows Server 2012 R2 (Server Core installation)
microsoftMicrosoft Visual Studio 2013 Update 5
microsoftMicrosoft Visual Studio 2015 Update 3
microsoftMicrosoft Word 2013 Service Pack 1 (32-bit editions)
microsoftMicrosoft Word 2013 Service Pack 1 (64-bit editions)
microsoftMicrosoft Word 2013 RT Service Pack 1
microsoftMicrosoft Office Web Apps Server 2013 Service Pack 1
microsoftMicrosoft SharePoint Foundation 2013 Service Pack 1
microsoftWindows 10 for 32-bit Systems
microsoftWindows 10 for x64-based Systems
microsoftMicrosoft Word 2016 (32-bit edition)
microsoftMicrosoft Word 2016 (64-bit edition)
microsoftWindows Server 2016
microsoftWindows 10 Version 1607 for 32-bit Systems
microsoftWindows 10 Version 1607 for x64-based Systems
microsoftWindows Server 2016 (Server Core installation)
microsoftMicrosoft SharePoint Enterprise Server 2016
microsoftMicrosoft SharePoint Enterprise Server 2013 Service Pack 1
microsoftMicrosoft SQL Server 2008 for 32-bit Systems Service Pack 4 (QFE)
microsoftMicrosoft SQL Server 2012 for 32-bit Systems Service Pack 4 (QFE)
microsoftMicrosoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE)
microsoftMicrosoft SQL Server 2017 for x64-based Systems (GDR)
microsoftMicrosoft SQL Server 2008 R2 for 32-Bit Systems Service Pack 3 (QFE)
microsoftMicrosoft SQL Server 2008 R2 for x64-Based Systems Service Pack 3 (QFE)

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.