logo

Windows CLFS and five exploits used by ransomware operators (Exploit #1 – CVE-2022-24521)

ID: 827331f2-c460-51d5-8281-ca36a38dacea

STIX ID: report--827331f2-c460-51d5-8281-ca36a38dacea

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2023-12-21

Date Updated: 2026-04-29

Author: Boris Larin

...
...

This report analyzes CVE-2022-24521 and a CLFS-based exploitation method where crafted BLF files overwrite client and container structures to make a kernel pointer equal to a controlled value, enabling an arbitrary QWORD decrement via CClfsContainer::Close and the well-known PreviousMode technique to escalate privileges; it documents active use in ransomware campaigns, sale of a 1‑day exploit on dark forums, and the attack chain including NtQuerySystemInformation, allocation at 0x40000000, and token replacement to achieve SYSTEM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.