ID:9809 - Exploit for Incorrect conversion between numeric types in Windows and Windows Server - CVE-2023-36900
Published: May 13, 2024
Windows
Windows Server
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect integer conversion in Windows Common Log File System driver (clfs.sys). A local user can create a specially crafted BLF file to trigger an incorrect integer calculation before allocating a buffer and execute arbitrary code on the system.