CVE-2023-28252: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
Other sources
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24216Patch KB5025272 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20919Patch KB5025288 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22015Patch KB5025273 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26466Patch KB5025277 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5850Patch KB5025228 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19869Patch KB5025234 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1555Patch KB5025239 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2846Patch KB5025221 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2846Patch KB5025221 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.1817Patch KB5025224 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2846Patch KB5025221 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1668Patch KB5025230 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4252Patch KB5025229
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28252?
CVE-2023-28252 is classified as a privilege escalation vulnerability in the Microsoft Windows Common Log File System driver.
How do I fix CVE-2023-28252?
To remediate CVE-2023-28252, apply the relevant patches provided by Microsoft for affected versions of Windows.
What versions of Windows are affected by CVE-2023-28252?
CVE-2023-28252 affects various versions of Windows including Windows 10, Windows Server 2008 R2, Windows Server 2016, and others.
How can CVE-2023-28252 be exploited?
CVE-2023-28252 can be exploited by attackers to gain elevated privileges on vulnerable systems.
Is there a known workaround for CVE-2023-28252 until a patch is applied?
Currently, there are no stated workarounds for CVE-2023-28252; applying the patches is recommended.