Windows CLFS and five exploits used by ransomware operators (Exploit #2 – September 2022)
ID: b6aff888-87be-5754-a046-00df845a4f2a
STIX ID: report--b6aff888-87be-5754-a046-00df845a4f2a
Feed Name: Securelist by Kaspersky
This part of the study analyzes a CLFS (Common Log File System) exploit that patches BLF files to relocate signature/original-byte arrays and fake CLFS structures, causing ClfsDecodeBlock/ClfsEncodeBlock to copy attacker-controlled data into record offsets and persist a malicious record; the write-up ties the technique to CVE-2022-37969 (a zero-day observed in the wild), explains the exploitation steps and abused APIs (SetLogArchiveMode, FlushMetadata), and notes these vulnerabilities have been used in ransomware attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
