Windows CLFS and five exploits used by ransomware operators
ID: 66c85e1b-ab34-5a60-930c-2db00eacc788
STIX ID: report--66c85e1b-ab34-5a60-930c-2db00eacc788
Feed Name: Securelist by Kaspersky
This report analyzes design and implementation flaws in the Windows Common Log File System (CLFS) driver and BLF file format that have led to numerous elevation-of-privilege vulnerabilities, including multiple zero-days observed in ransomware attacks. It documents CLFS internals, block/record layout, symbol and context structures, and explains how malformed BLF data and overlapping/invalid offsets can be leveraged to inject malicious CLFS_CONTAINER_CONTEXT structures and hijack kernel control flow.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
