{"cveID":"CVE-2023-28252","vendorProject":"Microsoft","product":"Windows","vulnerabilityName":"Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability","dateAdded":"2023-04-11","shortDescription":"Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2023-05-02","knownRansomwareCampaignUse":"Known","notes":"https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-28252;  https://nvd.nist.gov/vuln/detail/CVE-2023-28252","cwes":["CWE-122"],"year":2023,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2023-28252","technique":"T1078","technique_name_at_mapping":"Valid Accounts","mapping_type":"exploitation_technique","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary that has gained local access to the victim system. If successfully exploited, the adversary would gain full SYSTEM level privileges. \n\nThis CVE has been leveraged in the wild by Storm-0506 involved deploying Black Basta ransomware, initiated through a Qakbot infection and exploiting a Windows vulnerability (CVE-2023-28252) to gain elevated privileges. The attackers used tools like Cobalt Strike and Pypykatz for credential theft and lateral movement, eventually creating an \"ESX Admins\" group to encrypt the ESXi file system and disrupt hosted VMs.","references":["https://www.kaspersky.com/blog/nokoyawa-zero-day-exploit/47788/","https://cybersecuritynews.com/ransomware-gangs-vmware-esxi-bypass-flaw/","https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-april-2023/","https://www.darkreading.com/vulnerabilities-threats/microsoft-patches-97-cves-including-zero-day-wormable-bugs","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-28252","technique":"T1003","technique_name_at_mapping":"OS Credential Dumping","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary that has gained local access to the victim system. If successfully exploited, the adversary would gain full SYSTEM level privileges. \n\nThis CVE has been leveraged in the wild by Storm-0506 involved deploying Black Basta ransomware, initiated through a Qakbot infection and exploiting a Windows vulnerability (CVE-2023-28252) to gain elevated privileges. The attackers used tools like Cobalt Strike and Pypykatz for credential theft and lateral movement, eventually creating an \"ESX Admins\" group to encrypt the ESXi file system and disrupt hosted VMs.\n\nBased on the described exploitation of CVE-2023-28252 and the associated attack activities, the following MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs) could be linked to this CVE:","references":["https://www.kaspersky.com/blog/nokoyawa-zero-day-exploit/47788/","https://cybersecuritynews.com/ransomware-gangs-vmware-esxi-bypass-flaw/","https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-april-2023/","https://www.darkreading.com/vulnerabilities-threats/microsoft-patches-97-cves-including-zero-day-wormable-bugs","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-28252","technique":"T1021","technique_name_at_mapping":"Remote Services","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary that has gained local access to the victim system. If successfully exploited, the adversary would gain full SYSTEM level privileges. \n\nThis CVE has been leveraged in the wild by Storm-0506 involved deploying Black Basta ransomware, initiated through a Qakbot infection and exploiting a Windows vulnerability (CVE-2023-28252) to gain elevated privileges. The attackers used tools like Cobalt Strike and Pypykatz for credential theft and lateral movement, eventually creating an \"ESX Admins\" group to encrypt the ESXi file system and disrupt hosted VMs.\n\nBased on the described exploitation of CVE-2023-28252 and the associated attack activities, the following MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs) could be linked to this CVE:","references":["https://www.kaspersky.com/blog/nokoyawa-zero-day-exploit/47788/","https://cybersecuritynews.com/ransomware-gangs-vmware-esxi-bypass-flaw/","https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-april-2023/","https://www.darkreading.com/vulnerabilities-threats/microsoft-patches-97-cves-including-zero-day-wormable-bugs","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-28252","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary that has gained local access to the victim system. If successfully exploited, the adversary would gain full SYSTEM level privileges. \n\nThis CVE has been leveraged in the wild by Storm-0506 involved deploying Black Basta ransomware, initiated through a Qakbot infection and exploiting a Windows vulnerability (CVE-2023-28252) to gain elevated privileges. The attackers used tools like Cobalt Strike and Pypykatz for credential theft and lateral movement, eventually creating an \"ESX Admins\" group to encrypt the ESXi file system and disrupt hosted VMs.\n\nBased on the described exploitation of CVE-2023-28252 and the associated attack activities, the following MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs) could be linked to this CVE:","references":["https://www.kaspersky.com/blog/nokoyawa-zero-day-exploit/47788/","https://cybersecuritynews.com/ransomware-gangs-vmware-esxi-bypass-flaw/","https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-april-2023/","https://www.darkreading.com/vulnerabilities-threats/microsoft-patches-97-cves-including-zero-day-wormable-bugs","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-28252","technique":"T1068","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"primary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary that has gained local access to the victim system. If successfully exploited, the adversary would gain full SYSTEM level privileges. \n\nThis CVE has been leveraged in the wild by Storm-0506 involved deploying Black Basta ransomware, initiated through a Qakbot infection and exploiting a Windows vulnerability (CVE-2023-28252) to gain elevated privileges. The attackers used tools like Cobalt Strike and Pypykatz for credential theft and lateral movement, eventually creating an \"ESX Admins\" group to encrypt the ESXi file system and disrupt hosted VMs.\n\nBased on the described exploitation of CVE-2023-28252 and the associated attack activities, the following MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs) could be linked to this CVE:","references":["https://www.kaspersky.com/blog/nokoyawa-zero-day-exploit/47788/","https://cybersecuritynews.com/ransomware-gangs-vmware-esxi-bypass-flaw/","https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-april-2023/","https://www.darkreading.com/vulnerabilities-threats/microsoft-patches-97-cves-including-zero-day-wormable-bugs","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-28252","technique":"T1136","technique_name_at_mapping":"Create Account","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary that has gained local access to the victim system. If successfully exploited, the adversary would gain full SYSTEM level privileges. \n\nThis CVE has been leveraged in the wild by Storm-0506 involved deploying Black Basta ransomware, initiated through a Qakbot infection and exploiting a Windows vulnerability (CVE-2023-28252) to gain elevated privileges. The attackers used tools like Cobalt Strike and Pypykatz for credential theft and lateral movement, eventually creating an \"ESX Admins\" group to encrypt the ESXi file system and disrupt hosted VMs.\n\nBased on the described exploitation of CVE-2023-28252 and the associated attack activities, the following MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs) could be linked to this CVE:","references":["https://www.kaspersky.com/blog/nokoyawa-zero-day-exploit/47788/","https://cybersecuritynews.com/ransomware-gangs-vmware-esxi-bypass-flaw/","https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-april-2023/","https://www.darkreading.com/vulnerabilities-threats/microsoft-patches-97-cves-including-zero-day-wormable-bugs","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-28252","technique":"T1486","technique_name_at_mapping":"Data Encrypted for Impact","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary that has gained local access to the victim system. If successfully exploited, the adversary would gain full SYSTEM level privileges. \n\nThis CVE has been leveraged in the wild by Storm-0506 involved deploying Black Basta ransomware, initiated through a Qakbot infection and exploiting a Windows vulnerability (CVE-2023-28252) to gain elevated privileges. The attackers used tools like Cobalt Strike and Pypykatz for credential theft and lateral movement, eventually creating an \"ESX Admins\" group to encrypt the ESXi file system and disrupt hosted VMs.\n\nBased on the described exploitation of CVE-2023-28252 and the associated attack activities, the following MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs) could be linked to this CVE:","references":["https://www.kaspersky.com/blog/nokoyawa-zero-day-exploit/47788/","https://cybersecuritynews.com/ransomware-gangs-vmware-esxi-bypass-flaw/","https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-april-2023/","https://www.darkreading.com/vulnerabilities-threats/microsoft-patches-97-cves-including-zero-day-wormable-bugs","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"OS Credential Dumping","name_at_mapping":"OS Credential Dumping","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":37,"has_detection_strategy":true},{"id":"T1021","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Remote Services","name_at_mapping":"Remote Services","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":11,"has_detection_strategy":true},{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1068","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Privilege Escalation","name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":31,"has_detection_strategy":true},{"id":"T1078","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Valid Accounts","name_at_mapping":"Valid Accounts","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":56,"has_detection_strategy":true},{"id":"T1136","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Create Account","name_at_mapping":"Create Account","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":3,"has_detection_strategy":true},{"id":"T1486","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data Encrypted for Impact","name_at_mapping":"Data Encrypted for Impact","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":16,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}