logo

Windows CLFS and five exploits used by ransomware operators (Exploit #4 – CVE-2023-23376)

ID: 3d6767a6-4b46-5704-8dd2-bef822852d5a

STIX ID: report--3d6767a6-4b46-5704-8dd2-bef822852d5a

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2023-12-21

Date Updated: 2026-04-29

Author: Boris Larin

...
...

This report analyzes CVE-2023-23376 in the Windows CLFS CONTROL record, describing the root cause, exploitation steps (malicious CLFS_CONTROL_RECORD, patched block headers, and index manipulation), and how the flaw enables arbitrary pointer usage, memory corruption and privilege escalation—techniques observed in ransomware attacks and related to earlier CLFS exploits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.