Microsoft disclosed multiple Windows local privilege escalation vulnerabilities affecting kernel-level drivers, including Windows Common Log File System (CLFS) Driver flaws tracked as CVE-2023-23376 and CVE-2023-28252, as well as a Windows Cloud Files Mini Filter Driver flaw tracked as CVE-2025-62454. All three issues were classified as Elevation of Privilege vulnerabilities in Microsoft's Security Update Guide.
The advisories indicate that successful exploitation could allow an attacker who already has access to a target system to gain higher privileges through vulnerable Windows driver components. The affected bugs span separate Windows subsystems but share the same core risk: attackers can abuse low-level driver weaknesses to move from limited access toward more powerful control over compromised machines, reinforcing the need to prioritize Microsoft security updates for Windows kernel and file-system-related components.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2025-62454, an elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver.
Microsoft published a Security Update Guide entry for CVE-2025-21271, an elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver.
Microsoft published a Security Update Guide entry for CVE-2024-30085, an elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver.
Microsoft published a Security Update Guide entry for CVE-2023-36696, an elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver.
Microsoft published a Security Update Guide entry for CVE-2023-28252, another elevation of privilege vulnerability in the Windows Common Log File System Driver.
Microsoft published a Security Update Guide entry for CVE-2023-23376, an elevation of privilege vulnerability in the Windows Common Log File System Driver.
6 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceportal.msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.