Windows CLFS and five exploits used by ransomware operators (Exploit #5 – CVE-2023-28252)
ID: f69176b4-2322-5a68-8152-dae2c0733f67
STIX ID: report--f69176b4-2322-5a68-8152-dae2c0733f67
Feed Name: Securelist by Kaspersky
This report analyzes CVE-2023-28252, a logical vulnerability in Windows CLFS used in Nokoyawa ransomware attacks. It details how inconsistent validation between CLFS encode/decode functions allows an attacker to corrupt the CONTROL block (by forcing a checksum-clear and write despite encode failure), subsequently causing ReadMetadataBlock to prefer a crafted CONTROL_SHADOW and enabling unchecked iExtendBlock/iFlushBlock values. The write-up compares this exploit to prior CLFS issues, outlines the exploit steps and mitigations (Microsoft patch in April 2023), and emphasizes continued monitoring for CLFS-related zero-days.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
