PT-2023-9403 · Microsoft · Windows Server 2022+5
Ricardo Narvaja
·
Published
2023-12-20
·
Updated
2024-08-19
·
CVE-2024-6768
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 (affected versions not specified)
Description
A Denial of Service in the CLFS.sys driver allows a malicious authenticated low-privilege user to cause a Blue Screen of Death via a forced call to the
KeBugCheckEx function. The vulnerability is caused by improper validation of specified quantities in input data, leading to an unrecoverable inconsistency. This flaw can be exploited to crash systems repeatedly, disrupting operations. The estimated number of potentially affected devices worldwide is not specified.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clfs.Sys
Windows 10
Windows 11
Windows Server 2016
Windows Server 2019
Windows Server 2022