Out-of-bounds read in Windows and Windows Server - CVE-2023-38144
Published: September 12, 2023 / Updated: September 14, 2023
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a boundary condition within the clfs.sys driver. A local user can open a specially crafted BLF file, trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.