PT-2023-9403 · Microsoft · Windows Server 2022+5

Ricardo Narvaja

·

Published

2023-12-20

·

Updated

2024-08-19

·

CVE-2024-6768

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 (affected versions not specified)
Description A Denial of Service in the CLFS.sys driver allows a malicious authenticated low-privilege user to cause a Blue Screen of Death via a forced call to the KeBugCheckEx function. The vulnerability is caused by improper validation of specified quantities in input data, leading to an unrecoverable inconsistency. This flaw can be exploited to crash systems repeatedly, disrupting operations. The estimated number of potentially affected devices worldwide is not specified.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2024-07225
CVE-2024-6768

Affected Products

Clfs.Sys
Windows 10
Windows 11
Windows Server 2016
Windows Server 2019
Windows Server 2022