logo

Windows CLFS and five exploits used by ransomware operators (Exploit #5 – CVE-2023-28252)

ID: f69176b4-2322-5a68-8152-dae2c0733f67

STIX ID: report--f69176b4-2322-5a68-8152-dae2c0733f67

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2023-12-21

Date Updated: 2026-04-29

Author: Boris Larin

...
...

This report analyzes CVE-2023-28252, a logical vulnerability in Windows CLFS used in Nokoyawa ransomware attacks. It details how inconsistent validation between CLFS encode/decode functions allows an attacker to corrupt the CONTROL block (by forcing a checksum-clear and write despite encode failure), subsequently causing ReadMetadataBlock to prefer a crafted CONTROL_SHADOW and enabling unchecked iExtendBlock/iFlushBlock values. The write-up compares this exploit to prior CLFS issues, outlines the exploit steps and mitigations (Microsoft patch in April 2023), and emphasizes continued monitoring for CLFS-related zero-days.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.