CVE-2023-36424: Microsoft Windows Out-of-Bounds Read Vulnerability
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
Other sources
Windows Common Log File System Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24569Patch KB5032247 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21668Patch KB5032249 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6452Patch KB5032197 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26816Patch KB5032250 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20308Patch KB5032199 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22367Patch KB5032248 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3693Patch KB5032189 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.3693Patch KB5032189 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.5122Patch KB5032196 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2600Patch KB5032192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.2715Patch KB5032190 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2113Fixed in 10.0.20348.2091Patch KB5032304 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.2715Patch KB5032190 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.531Patch KB5032202
Event History
Frequently Asked Questions
What is CVE-2023-36424?
CVE-2023-36424 is a Windows Common Log File System Driver Elevation of Privilege Vulnerability.
Which software products are affected by CVE-2023-36424?
CVE-2023-36424 affects various versions of Windows Server 2008, Windows 10, Windows 11, Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2022, 23H2 Edition.
What is the severity rating of CVE-2023-36424?
CVE-2023-36424 has a severity rating of 7.8 (high).
How can I fix CVE-2023-36424?
You can fix CVE-2023-36424 by applying the relevant security patches provided by Microsoft or following the recommended remediation steps outlined in the official Microsoft support articles.
Where can I find more information about CVE-2023-36424?
You can find more information about CVE-2023-36424 on the official Microsoft Security Response Center (MSRC) website.