#VU79225 Incorrect conversion between numeric types in Windows and Windows Server - CVE-2023-36900
Published: August 8, 2023 / Updated: May 13, 2024
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect integer conversion in Windows Common Log File System driver (clfs.sys). A local user can create a specially crafted BLF file to trigger an incorrect integer calculation before allocating a buffer and execute arbitrary code on the system.