๐Ÿ” CVE Alert

CVE-2023-36424

HIGH 7.8 โš ๏ธ CISA KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS Score
7.8
EPSS Score
10.3%
EPSS Percentile
93th

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Vendor microsoft
Product windows 11 version 22h3
Ecosystems
Industries
TechnologyEnterprise
Published Nov 14, 2023
Last Updated Apr 14, 2026
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for microsoft windows 11 version 22h3

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2023-36424.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Microsoft / Windows 11 version 22H3
10.0.22631.0 < 10.0.22631.2715
Microsoft / Windows Server 2022, 23H2 Edition (Server Core installation)
10.0.25398.0 < 10.0.25398.531
Microsoft / Windows 11 Version 23H2
10.0.22631.0 < 10.0.22631.2715
Microsoft / Windows 10 Version 1809
10.0.17763.0 < 10.0.17763.5122
Microsoft / Windows 10 Version 1809
10.0.0 < 10.0.17763.5122
Microsoft / Windows Server 2019
10.0.17763.0 < 10.0.17763.5122
Microsoft / Windows Server 2019 (Server Core installation)
10.0.17763.0 < 10.0.17763.5122
Microsoft / Windows Server 2022
10.0.20348.0 < 10.0.20348.2113
Microsoft / Windows 11 version 21H2
10.0.0 < 10.0.22000.2600
Microsoft / Windows 10 Version 21H2
10.0.19043.0 < 10.0.19043.3693
Microsoft / Windows 11 version 22H2
10.0.22621.0 < 10.0.22621.2715
Microsoft / Windows 10 Version 22H2
10.0.19045.0 < 10.0.19045.3693
Microsoft / Windows 10 Version 1507
10.0.10240.0 < 10.0.10240.20308
Microsoft / Windows 10 Version 1607
10.0.14393.0 < 10.0.14393.6452
Microsoft / Windows Server 2016
10.0.14393.0 < 10.0.14393.6452
Microsoft / Windows Server 2016 (Server Core installation)
10.0.14393.0 < 10.0.14393.6452
Microsoft / Windows Server 2008 Service Pack 2
6.0.6003.0 < 6.0.6003.22367
Microsoft / Windows Server 2008 Service Pack 2 (Server Core installation)
6.0.6003.0 < 6.0.6003.22367
Microsoft / Windows Server 2008 Service Pack 2
6.0.6003.0 < 6.0.6003.22367
Microsoft / Windows Server 2008 R2 Service Pack 1
6.1.7601.0 < 6.1.7601.26816
Microsoft / Windows Server 2008 R2 Service Pack 1 (Server Core installation)
6.1.7601.0 < 6.1.7601.26816
Microsoft / Windows Server 2012
6.2.9200.0 < 6.2.9200.24569
Microsoft / Windows Server 2012 (Server Core installation)
6.2.9200.0 < 6.2.9200.24569
Microsoft / Windows Server 2012 R2
6.3.9600.0 < 6.3.9600.21668
Microsoft / Windows Server 2012 R2 (Server Core installation)
6.3.9600.0 < 6.3.9600.21668

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
msrc.microsoft.com: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36424 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-36424