Windows CLFS and five exploits used by ransomware operators (Exploit #3 – October 2022)
ID: 13f4b093-6ccc-51e2-b1f6-0316298b4739
STIX ID: report--13f4b093-6ccc-51e2-b1f6-0316298b4739
Feed Name: Securelist by Kaspersky
Threat Score
This part of a multi-part analysis details Exploit #3 against the Windows CLFS driver (October 2022), describing how an attacker patches BLF file fields to create overlapping CLFS structures and overwrite kernel pointers; the exploit is closely related to previously reported CVEs and was observed used in ransomware attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
