Windows CLFS and five exploits used by ransomware operators (Exploit #4 – CVE-2023-23376)
ID: 3d6767a6-4b46-5704-8dd2-bef822852d5a
STIX ID: report--3d6767a6-4b46-5704-8dd2-bef822852d5a
Feed Name: Securelist by Kaspersky
Threat Score
This report analyzes CVE-2023-23376 in the Windows CLFS CONTROL record, describing the root cause, exploitation steps (malicious CLFS_CONTROL_RECORD, patched block headers, and index manipulation), and how the flaw enables arbitrary pointer usage, memory corruption and privilege escalation—techniques observed in ransomware attacks and related to earlier CLFS exploits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
