CLFS Bug Crashes Even Updated Windows 10, 11 Systems
ID: d9b7f956-ea46-5eb0-97eb-0d0fdcd53fae
STIX ID: report--d9b7f956-ea46-5eb0-97eb-0d0fdcd53fae
Feed Name: Dark Reading
A Fortra researcher disclosed CVE-2024-6768: a medium-severity flaw in the Windows Common Log File System (CLFS) driver where crafted base log files with bad size validation for the "IsnOwnerPage" field cause immediate system crashes (BSoD) across Windows 10, 11, and Server 2022. A public PoC reliably triggers crashes, Windows Defender flags the PoC as malware, and Microsoft has declined to provide an immediate fix, stating the technique requires prior code execution and does not grant elevated permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
