logo

Windows CLFS and five exploits used by ransomware operators (Exploit #3 – October 2022)

ID: 13f4b093-6ccc-51e2-b1f6-0316298b4739

STIX ID: report--13f4b093-6ccc-51e2-b1f6-0316298b4739

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2023-12-21

Date Updated: 2026-04-29

Author: Boris Larin

...
...

This part of a multi-part analysis details Exploit #3 against the Windows CLFS driver (October 2022), describing how an attacker patches BLF file fields to create overlapping CLFS structures and overwrite kernel pointers; the exploit is closely related to previously reported CVEs and was observed used in ransomware attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.