{"id":29587,"date":"2023-04-12T15:26:02","date_gmt":"2023-04-12T15:26:02","guid":{"rendered":"https:\/\/www.esecurityplanet.com\/?p=29587"},"modified":"2023-04-12T15:26:04","modified_gmt":"2023-04-12T15:26:04","slug":"windows-clfs-vulnerability-ransomware","status":"publish","type":"post","link":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/","title":{"rendered":"Windows CLFS Vulnerability Used for Ransomware Attacks"},"content":{"rendered":"\n<p>Microsoft&#8217;s Patch Tuesday for April 2023 targets 97 vulnerabilities, seven of them rated critical \u2013 as well as one that&#8217;s currently being exploited in the wild.<\/p>\n\n\n\n<p>The one flaw that\u2019s currently being exploited, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2023-28252\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-28252<\/a>, is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) Driver that could provide an attacker with SYSTEM privileges. Qualys director of vulnerability and threat research Bharat Jogi noted that the flaw, which has a CVSS score of 7.8, is already being used by cybercriminals to deploy Nokoyawa <a href=\"https:\/\/www.esecurityplanet.com\/threats\/ransomware\/\">ransomware<\/a>.<\/p>\n\n\n\n<p>The seven critical vulnerabilities, all of them remote code execution (RCE) flaws, are as follows:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-21554\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-21554<\/a>, a flaw in Microsoft Message Queuing with a CVSS score of 9.8<\/li>\n\n\n\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28219\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-28219<\/a> and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28220\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-28220<\/a>, a pair of flaws in the Layer 2 Tunneling Protocol with a CVSS score of 8.1<\/li>\n\n\n\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28231\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-28231<\/a>, a flaw in DHCP Server Service with a CVSS score of 8.8<\/li>\n\n\n\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28232\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-28232<\/a>, a flaw in the Windows Point-to-Point Tunneling Protocol with a CVSS score of 7.5<\/li>\n\n\n\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28250\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-28250<\/a>, a flaw in Windows Pragmatic General Multicast (PGM) with a CVSS score of 9.8<\/li>\n\n\n\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28291\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-28291<\/a>, a flaw in the Raw Image Extension with a CVSS score of 8.4<\/li>\n<\/ul>\n\n\n\n<p>Two of the seven are particularly noteworthy. &#8220;CVE-2023-28231 (DHCP Server Service Remote Code Execution Vulnerability) and CVE-2023-21554 (Microsoft Message Queuing Remote Code Execution Vulnerability) are both critical-severity RCEs submitted to Microsoft by external security researchers, and both are flagged by Microsoft as more likely to be exploited within the next 30 days,&#8221; Sophos senior threat researcher Angela Gunn <a href=\"https:\/\/news.sophos.com\/en-us\/2023\/04\/11\/april-showers-windows-updates-on-sysadmins\/\" target=\"_blank\" rel=\"noreferrer noopener\">observed<\/a>.<\/p>\n\n\n\n<p><strong>Also read: <\/strong><a href=\"https:\/\/www.esecurityplanet.com\/applications\/patch-management-as-a-service\/\"><strong>Is the Answer to Vulnerabilities Patch Management as a Service?<\/strong><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Nokoyawa Ransomware Leverages Flaw<\/h2>\n\n\n\n<p>Nokoyawa ransomware &#8220;is a relatively new strain for which there is some open-source intel to suggest that it is possibly related to Hive ransomware \u2013 one of the most notable ransomware families of 2021 and linked to breaches of over 300+ organizations in a matter of just a few months,&#8221; said Jogi said.<\/p>\n\n\n\n<p>&#8220;While it is still unclear who the exact threat actor or APT group is using Nokoyawa, targets have been observed in South and North America, regions across Asia, and SMBs in the Middle East,&#8221; he added.<\/p>\n\n\n\n<p>Jogi noted that this isn&#8217;t the first time a flaw in the Windows Common Log File System Driver has been leveraged by threat actors. &#8220;In September 2022, Microsoft fixed another vulnerability \u2013 <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37969\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2022-37969<\/a>, which was known to be exploited in the wild \u2013 that affected this same component,&#8221; he said. &#8220;CVE-2022-37969 was leveraged by an unknown threat actor to gain elevated privileges once they had a foothold on the system.&#8221;<\/p>\n\n\n\n<p><strong>Also read: <\/strong><a href=\"https:\/\/www.esecurityplanet.com\/threats\/ransomware-protection\/\"><strong>Ransomware Protection: How to Prevent Ransomware Attacks<\/strong><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Two Additional Vulnerabilities of Note<\/h2>\n\n\n\n<p>RCE flaws have comprised most of the critical Microsoft flaws so far this year (image below from Sophos).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.esecurityplanet.com\/wp-content\/uploads\/2023\/04\/windows-rce-flaws-1024x663.jpg\" alt=\"Microsoft vulnerabilities in 2023\" class=\"wp-image-29588\" width=\"768\" height=\"497\" srcset=\"https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws-1024x663.jpg 1024w, https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws-300x194.jpg 300w, https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws-768x497.jpg 768w, https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws-1536x995.jpg 1536w, https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws-2048x1326.jpg 2048w, https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws-150x97.jpg 150w, https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws-696x451.jpg 696w, https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws-1068x692.jpg 1068w, https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws-1920x1243.jpg 1920w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/><figcaption class=\"wp-element-caption\">Microsoft vulnerabilities in 2023<\/figcaption><\/figure>\n\n\n\n<p>Action1 vice president of vulnerability and threat research Mike Walters <a href=\"https:\/\/www.action1.com\/patch-tuesday-april-2023\/\" target=\"_blank\" rel=\"noreferrer noopener\">highlighted<\/a> two additional RCE flaws from the current updates. The first, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28311\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2023-28311<\/a>, is a remote code execution vulnerability in Microsoft Word with a CVE score of 7.8.<\/p>\n\n\n\n<p>&#8220;Although it is considered low complexity and does not require privileges to exploit, it does require user interaction and cannot be exploited through the Preview pane,&#8221; Walters wrote. &#8220;This means that an attacker must send a malicious file to the user and convince them to open it. While Microsoft says this vulnerability is less likely to be exploited, it is still recommended to update your Microsoft 365 applications to the latest version as a precaution.&#8221;<\/p>\n\n\n\n<p>The second, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2013-3900\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2013-3900<\/a>, is a decade-old remote code execution vulnerability in WinVerifyTrust Signature Validation that Microsoft is republishing &#8220;to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11,&#8221; according to the company.<\/p>\n\n\n\n<p>&#8220;An attacker who successfully exploited this vulnerability could take complete control of the affected system,&#8221; Microsoft added.<\/p>\n\n\n\n<p>&#8220;While the current patches don&#8217;t directly address this vulnerability, the mitigation is already built into the latest OS versions, and can be enabled manually in the registry if desired,&#8221; Walters noted. &#8220;Microsoft suggests that developers ensure their signed binaries conform to the new verification standard by eliminating any extraneous information in the WIN_CERTIFICATE structure, and recommends that customers test this change to evaluate its impact in their own environments.&#8221;<\/p>\n\n\n\n<p><strong>Read next: <\/strong><a href=\"https:\/\/www.esecurityplanet.com\/products\/patch-management-software\/\"><strong>Best Patch Management Software &amp; Tools for 2023<\/strong><\/a><\/p>\n\n\n<div id=\"ta-campaign-widget-66d6ff1fb495c-popup-wrapper\" class=\"ta-campaign-widget__popup-wrapper\">\n    \n<div\n    style=\"\n        --ta-campaign-plugin-primary: #3545ed;\n        --ta-campaign-plugin-button-text: #fff;\n        --ta-campaign-plugin-button-hover-background: #3231b4;\n        --ta-campaign-plugin-button-hover-text: #fff;\n        --ta-campaign-plugin-button-toggle-background: #3231b4;\n        --ta-campaign-plugin-button-toggle-text: #3231B4;\n    \"\n    data-ajax-url=\"https:\/\/www.esecurityplanet.com\/wp\/wp-admin\/admin-ajax.php\">\n    <div\n        id=\"ta-campaign-widget-66d6ff1fb495c\"\n        class=\"ta-campaign-widget ta-campaign-widget--popup\"\n        data-campaign-fields='{\"properties\":{\"campaign_type\":\"popup\",\"campaign_category\":false,\"sailthru_list\":[\"cybersecurity-insider\"],\"popup_type\":\"exit_intent\",\"appearance\":{\"colors\":{\"primary_color\":\"#3545ed\",\"button\":{\"button_text_color\":\"#fff\",\"hover\":{\"button_hover_background_color\":\"#3231b4\",\"button_hover_text_color\":\"#fff\"},\"toggle\":{\"button_toggle_background_color\":\"#3231b4\",\"button_toggle_text_color\":\"#3231B4\"}}},\"custom_scss\":\"\"},\"behavior\":{\"opt_in_enabled\":true},\"language\":{\"tagline\":\"Get the Free Cybersecurity Newsletter\",\"subtagline\":\"\",\"content\":\"Strengthen your organization&#39;s IT security defenses by keeping up to date on the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday\",\"email_placeholder\":\"Work Email Address\",\"opt_in\":\"By signing up to receive our newsletter, you agree to our Terms of Use and Privacy Policy. You can unsubscribe at any time.\",\"subscribe_button\":\"Subscribe\"}},\"identifier\":\"66d6ff1fb495c\",\"campaign_id\":26045,\"campaign_type\":\"popup\",\"popup_type\":\"exit_intent\",\"newsletters\":[\"cybersecurity-insider\"],\"behavior\":{\"opt_in_enabled\":true},\"appearance\":{\"colors\":{\"primary\":\"#3545ed\",\"button\":{\"text\":\"#fff\",\"hover\":{\"background\":\"#3231b4\",\"text\":\"#fff\"},\"toggle\":{\"background\":\"#3231b4\",\"text\":\"#3231B4\"}}},\"custom_css\":\"\"},\"language\":{\"tagline\":\"Get the Free Cybersecurity Newsletter\",\"subtagline\":\"\",\"content\":\"Strengthen your organization&#39;s IT security defenses by keeping up to date on the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday\",\"email_placeholder\":\"Work Email Address\",\"opt_in\":\"By signing up to receive our newsletter, you agree to our Terms of Use and Privacy Policy. You can unsubscribe at any time.\",\"subscribe_button\":\"Subscribe\"}}'>\n\n                <div class=\"ta-campaign-widget__exit\">\n            <svg class=\"w-8\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" viewBox=\"0 0 24 24\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\">\n                <path stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M6 18L18 6M6 6l12 12\"><\/path>\n            <\/svg>\n        <\/div>\n        \n        <div class=\"ta-campaign-widget__wrapper\">\n            <div class=\"ta-campaign-widget__header mb-6\">\n                                <h3 class=\"ta-campaign-widget__tagline\">\n                    Get the Free Cybersecurity Newsletter                <\/h3>\n                \n                \n                                <p class=\"ta-campaign-widget__content mt-6\">\n                    Strengthen your organization's IT security defenses by keeping up to date on the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday                <\/p>\n                            <\/div>\n\n            <form class=\"ta-campaign-widget__form\">\n                <div class=\"ta-campaign-widget__input mb-4\"  data-field=\"email\">\n                    <label\n                        class=\"sr-only\"\n                        for=\"email-66d6ff1fb495c\">\n                        Email Address\n                    <\/label>\n                    <input\n                        class=\"ta-campaign-widget__input__text\"\n                        placeholder=\"Work Email Address\"\n                        id=\"email-66d6ff1fb495c\"\n                        name=\"email\"\n                        type=\"email\">\n                <\/div>\n\n                                <div class=\"ta-campaign-widget__checkbox mb-4\" data-field=\"opt_in\">\n                    <div class=\"flex items-start\">\n                        <input\n                            id=\"opt-in-66d6ff1fb495c\"\n                            class=\"ta-campaign-widget__checkbox__input mr-2\"\n                            name=\"opt-in\"\n                            type=\"checkbox\"\/>\n                        <label\n                            class=\"ta-campaign-widget__checkbox__label\"\n                            for=\"opt-in-66d6ff1fb495c\">\n                            By signing up to receive our newsletter, you agree to our Terms of Use and Privacy Policy. You can unsubscribe at any time.                        <\/label>\n                    <\/div>\n                <\/div>\n                \n                <button class=\"ta-campaign-widget__button\" type=\"submit\" >\n                    Subscribe                <\/button>\n            <\/form>\n        <\/div>\n    <\/div>\n<\/div>\n\n<style>\n<\/style><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft&#8217;s Patch Tuesday for April 2023 targets 97 vulnerabilities, seven of them rated critical \u2013 as well as one that&#8217;s currently being exploited in the wild. The one flaw that\u2019s currently being exploited, CVE-2023-28252, is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) Driver that could provide an attacker with [&hellip;]<\/p>\n","protected":false},"author":166,"featured_media":29588,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_gazelle_contributing_experts":"","footnotes":""},"categories":[15],"tags":[3790,532,3414,23006,2478,730,4218,5277],"b2b_audience":[33,35],"b2b_industry":[],"b2b_product":[382,378,31780,31790,392],"class_list":["post-29587","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threats","tag-cybersecurity","tag-microsoft","tag-network-security","tag-patch-management","tag-ransomware","tag-security","tag-vulnerabilities","tag-web-security","b2b_audience-awareness-and-consideration","b2b_audience-implementation-and-support","b2b_product-application-security-vulnerability-management","b2b_product-endpoint-security","b2b_product-patch-management","b2b_product-ransomware","b2b_product-web-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Windows CLFS Vulnerability Used for Ransomware Attacks | eSecurity Planet<\/title>\n<meta name=\"description\" content=\"Microsoft&#039;s April 2023 Patch Tuesday fixes 97 flaws, including one that&#039;s being actively exploited by a ransomware group.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Windows CLFS Vulnerability Used for Ransomware Attacks | eSecurity Planet\" \/>\n<meta property=\"og:description\" content=\"Microsoft&#039;s April 2023 Patch Tuesday fixes 97 flaws, including one that&#039;s being actively exploited by a ransomware group.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/\" \/>\n<meta property=\"og:site_name\" content=\"eSecurity Planet\" \/>\n<meta property=\"article:published_time\" content=\"2023-04-12T15:26:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-04-12T15:26:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2088\" \/>\n\t<meta property=\"og:image:height\" content=\"1352\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jeff Goldman\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@eSecurityPlanet\" \/>\n<meta name=\"twitter:site\" content=\"@eSecurityPlanet\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeff Goldman\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/\"},\"author\":{\"name\":\"Jeff Goldman\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/814377f0182cc43200a4581fba4ec795\"},\"headline\":\"Windows CLFS Vulnerability Used for Ransomware Attacks\",\"datePublished\":\"2023-04-12T15:26:02+00:00\",\"dateModified\":\"2023-04-12T15:26:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/\"},\"wordCount\":713,\"publisher\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws.jpg\",\"keywords\":[\"cybersecurity\",\"Microsoft\",\"network security\",\"Patch Management\",\"ransomware\",\"security\",\"vulnerabilities\",\"Web security\"],\"articleSection\":[\"Threats\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/\",\"url\":\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/\",\"name\":\"Windows CLFS Vulnerability Used for Ransomware Attacks | eSecurity Planet\",\"isPartOf\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws.jpg\",\"datePublished\":\"2023-04-12T15:26:02+00:00\",\"dateModified\":\"2023-04-12T15:26:04+00:00\",\"description\":\"Microsoft's April 2023 Patch Tuesday fixes 97 flaws, including one that's being actively exploited by a ransomware group.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#primaryimage\",\"url\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws.jpg\",\"contentUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws.jpg\",\"width\":2088,\"height\":1352},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.esecurityplanet.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Windows CLFS Vulnerability Used for Ransomware Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#website\",\"url\":\"https:\/\/www.esecurityplanet.com\/\",\"name\":\"eSecurity Planet\",\"description\":\"Industry-leading guidance and analysis for how to keep your business secure.\",\"publisher\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.esecurityplanet.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#organization\",\"name\":\"eSecurityPlanet\",\"url\":\"https:\/\/www.esecurityplanet.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png\",\"contentUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png\",\"width\":1134,\"height\":375,\"caption\":\"eSecurityPlanet\"},\"image\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/eSecurityPlanet\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/814377f0182cc43200a4581fba4ec795\",\"name\":\"Jeff Goldman\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/08\/jeff-goldman-150x150.jpg\",\"contentUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/08\/jeff-goldman-150x150.jpg\",\"caption\":\"Jeff Goldman\"},\"description\":\"eSecurity Planet contributor Jeff Goldman has been a technology journalist for more than 20 years and an eSecurity Planet contributor since 2009. He's also written extensively about wireless and broadband infrastructure and semiconductor engineering. He started his career at MTV, but soon decided that technology writing was a more promising path.\",\"url\":\"https:\/\/www.esecurityplanet.com\/author\/jeff-goldman\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Windows CLFS Vulnerability Used for Ransomware Attacks | eSecurity Planet","description":"Microsoft's April 2023 Patch Tuesday fixes 97 flaws, including one that's being actively exploited by a ransomware group.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/","og_locale":"en_US","og_type":"article","og_title":"Windows CLFS Vulnerability Used for Ransomware Attacks | eSecurity Planet","og_description":"Microsoft's April 2023 Patch Tuesday fixes 97 flaws, including one that's being actively exploited by a ransomware group.","og_url":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/","og_site_name":"eSecurity Planet","article_published_time":"2023-04-12T15:26:02+00:00","article_modified_time":"2023-04-12T15:26:04+00:00","og_image":[{"width":2088,"height":1352,"url":"https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws.jpg","type":"image\/jpeg"}],"author":"Jeff Goldman","twitter_card":"summary_large_image","twitter_creator":"@eSecurityPlanet","twitter_site":"@eSecurityPlanet","twitter_misc":{"Written by":"Jeff Goldman","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#article","isPartOf":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/"},"author":{"name":"Jeff Goldman","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/814377f0182cc43200a4581fba4ec795"},"headline":"Windows CLFS Vulnerability Used for Ransomware Attacks","datePublished":"2023-04-12T15:26:02+00:00","dateModified":"2023-04-12T15:26:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/"},"wordCount":713,"publisher":{"@id":"https:\/\/www.esecurityplanet.com\/#organization"},"image":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws.jpg","keywords":["cybersecurity","Microsoft","network security","Patch Management","ransomware","security","vulnerabilities","Web security"],"articleSection":["Threats"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/","url":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/","name":"Windows CLFS Vulnerability Used for Ransomware Attacks | eSecurity Planet","isPartOf":{"@id":"https:\/\/www.esecurityplanet.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#primaryimage"},"image":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws.jpg","datePublished":"2023-04-12T15:26:02+00:00","dateModified":"2023-04-12T15:26:04+00:00","description":"Microsoft's April 2023 Patch Tuesday fixes 97 flaws, including one that's being actively exploited by a ransomware group.","breadcrumb":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#primaryimage","url":"https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws.jpg","contentUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2023\/04\/windows-rce-flaws.jpg","width":2088,"height":1352},{"@type":"BreadcrumbList","@id":"https:\/\/www.esecurityplanet.com\/threats\/windows-clfs-vulnerability-ransomware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.esecurityplanet.com\/"},{"@type":"ListItem","position":2,"name":"Windows CLFS Vulnerability Used for Ransomware Attacks"}]},{"@type":"WebSite","@id":"https:\/\/www.esecurityplanet.com\/#website","url":"https:\/\/www.esecurityplanet.com\/","name":"eSecurity Planet","description":"Industry-leading guidance and analysis for how to keep your business secure.","publisher":{"@id":"https:\/\/www.esecurityplanet.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.esecurityplanet.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.esecurityplanet.com\/#organization","name":"eSecurityPlanet","url":"https:\/\/www.esecurityplanet.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/","url":"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png","contentUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png","width":1134,"height":375,"caption":"eSecurityPlanet"},"image":{"@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/eSecurityPlanet"]},{"@type":"Person","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/814377f0182cc43200a4581fba4ec795","name":"Jeff Goldman","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/image\/","url":"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/08\/jeff-goldman-150x150.jpg","contentUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/08\/jeff-goldman-150x150.jpg","caption":"Jeff Goldman"},"description":"eSecurity Planet contributor Jeff Goldman has been a technology journalist for more than 20 years and an eSecurity Planet contributor since 2009. He's also written extensively about wireless and broadband infrastructure and semiconductor engineering. He started his career at MTV, but soon decided that technology writing was a more promising path.","url":"https:\/\/www.esecurityplanet.com\/author\/jeff-goldman\/"}]}},"_links":{"self":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/posts\/29587"}],"collection":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/users\/166"}],"replies":[{"embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/comments?post=29587"}],"version-history":[{"count":0,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/posts\/29587\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/media\/29588"}],"wp:attachment":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/media?parent=29587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/categories?post=29587"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/tags?post=29587"},{"taxonomy":"b2b_audience","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/b2b_audience?post=29587"},{"taxonomy":"b2b_industry","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/b2b_industry?post=29587"},{"taxonomy":"b2b_product","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/b2b_product?post=29587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}