logo

Windows CLFS and five exploits used by ransomware operators

ID: 66c85e1b-ab34-5a60-930c-2db00eacc788

STIX ID: report--66c85e1b-ab34-5a60-930c-2db00eacc788

Feed Name: Securelist by Kaspersky

Threat Score
85/100

Date Published: 2023-12-21

Date Updated: 2026-04-29

Author: Boris Larin

...
...

This report analyzes design and implementation flaws in the Windows Common Log File System (CLFS) driver and BLF file format that have led to numerous elevation-of-privilege vulnerabilities, including multiple zero-days observed in ransomware attacks. It documents CLFS internals, block/record layout, symbol and context structures, and explains how malformed BLF data and overlapping/invalid offsets can be leveraged to inject malicious CLFS_CONTAINER_CONTEXT structures and hijack kernel control flow.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.