CVE-2023-36424Active Exploitation(microsoft / windows_10_1507)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-125

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-04-13); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_11_23h2windows_server_2008windows_server_2012

2 versions affected across 14 products

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-04-13: 4Mentions · 2026-04-14: 2Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-14: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-04-14: 2Active Exploitation · 2026-04-15: 1Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-13: 4Technical Details · 2026-04-14: 2Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 104-1304-1404-1504-16
Signal classification4 categories
Active Exploitation
450.0%
Disclosure
225.0%
General
112.5%
Patch
112.5%
Referenced assets20 URLs
Classification over time
DateTotalLabels
2026-04-134
Active Exploitation1Disclosure1General1Patch1
2026-04-142
Active Exploitation2
2026-04-151
Active Exploitation1
2026-04-161
Disclosure1
Full discourse8 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    6 ثغرات تهدد اغلب الاجهزة والشبكات يتم استغلالها حاليا 🚨 CISA أضافت 6 ثغرات جديدة لقائمة (KEV)Known Exploited Vulnerabilities بعد تأكد الاستغلال الفعلي لها حاليا من قبل المخترقين. الثغرة CVE-2026-21643 (CVSS: 9.1) 🔴 المنتج: FortiClient EMS من Fortinet النوع: SQL Injection التأثير: تنفيذ كود خبيث بدون مصادقة الحالة: استغلال مؤكد منذ 24 مارس 2026 الثغرة CVE-2020-9715 (CVSS: 7.8)🟠 المنتج: Adobe Acrobat Reader النوع: Use-After-Free التأثير: Remote Code Execution ثغرة تستغل من (2020) ولكن تم اكتشافها والاعلان عنها مؤخرا الثغرة CVE-2023-36424 (CVSS: 7.8) 🟠 المنتج: Microsoft Windows Common Log File System Driver النوع: Out-of-Bounds Read التأثير: Privilege Escalation ما فيه تقارير استغلال علنية، بس CISA تؤكد انها تتسغل حاليا . الثغرة CVE-2023-21529 (CVSS: 8.8) 🔴 المنتج: Microsoft Exchange Server النوع: Deserialization of Untrusted Data التأثير: Remote Code Execution المجموعة الصينية Storm-1175 تستغلها لـ Medusa Ransomware. الثغرة CVE-2025-60710 (CVSS: 7.8)🟠 المنتج: Host Process for Windows Tasks النوع: Improper Link Resolution Before File Access التأثير: Local Privilege Escalation الثغرة CVE-2012-1854 (CVSS: 7.8) 📅🟠 المنتج: Microsoft Visual Basic for Applications (VBA) النوع: Insecure Library Loading التأثير: Remote Code Execution ثغرة من 2012! Microsoft عمرها ١٤ سنه ولاتزال تستغل

    Post summary

    Six CVEs are confirmed as actively exploited; technical details are provided, but no PoC, patch or exploit code is referenced.

    16020152.6K
    49.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/13追加) 🛡️No.1561 CVE-2012-1854 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability ✅概要 ・深刻度:重要 7.8 (CVSS Base) / CISA-ADP ・種別:信頼できない検索パス (CWE-426) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft Visual Basic for Applications (VBA) において、DLL検索パスの処理に不備が存在。事前認証されていない攻撃者により、細工されたDLLを特定ディレクトリに配置されることで、正規ライブラリにかわって読み込まされる恐れがある。結果、ユーザーが対象ファイルを開くことで、任意コードが実行される可能性がある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・攻撃者がDLLを配置できる環境であること ・ユーザーが細工されたファイルを開くこと ・VBAが有効な環境 ________________________________________ ✅悪用時影響 ・任意コード実行(ユーザー権限) ・情報漏えいおよび改ざん ・システム可用性への影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2012-1854 https://learn.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-046   🛡️No.1562 CVE-2025-60710 Microsoft Windows Link Following Vulnerability ✅概要 ・深刻度:重要 7.8 (CVSS Base) / Microsoft Corporation ・種別:リンク解釈の問題 (CWE-59) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Windows において、リンク解決処理に不備が存在。認証済みの攻撃者により、細工されたリンクを介して、本来アクセスできないリソースへアクセスされ、ローカル環境で権限昇格される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・ローカルアクセスが可能であること ・低権限ユーザーであること ・ユーザー操作不要 ________________________________________ ✅悪用時影響 ・権限昇格 ・機密情報の取得および改ざん ・システムへの影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-60710 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710   🛡️No.1563 CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability ✅概要 ・深刻度:8.8 High (CVSS Base) / NVD ・種別:信頼できないデータのデシリアライゼーション (CWE-502) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Exchange Serverにおいて、信頼できないデータのデシリアライズ処理に起因する脆弱性が存在。認証済みの攻撃者により、細工されたデータをサーバー上で処理されることで、コード実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・認証済みユーザ権限が必要 ・Exchange Serverへのネットワークアクセス ________________________________________ ✅悪用時影響 ・任意コード実行 ・情報漏えい、改ざん、サービス影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-21529 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21529   🛡️No.1564 CVE-2023-36424 Microsoft Windows Out-of-Bounds Read Vulnerability ✅概要 ・深刻度:7.8 High (CVSS Base) / NVD ・種別:境界外読み取り (CWE-125) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Microsoft Windowsにおいて、境界外読み取りに起因する脆弱性が存在。認証済みの攻撃者により、不正なメモリアクセスを引き起こされることで、機密情報を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:高 ________________________________________ ✅攻撃前提条件 ・ローカルでのログオン権限が必要 ________________________________________ ✅悪用時影響 ・機密情報の漏えい ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-36424 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36424   🛡️No.1565 CVE-2020-9715 Adobe Acrobat Use-After-Free Vulnerability ✅概要 ・深刻度:7.8 High (CVSS Base) / NVD ・種別:解放後使用 (CWE-416) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Adobe AcrobatおよびReaderにおいて、解放後使用に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたPDFファイルをユーザーに開かせることで、メモリ破損を引き起こし、任意のコードを実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・ユーザが細工されたPDFファイルを開く必要がある ________________________________________ ✅悪用時影響 ・任意コード実行 ・情報の取得、改ざん、システム影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2020-9715 https://helpx.adobe.com/security/products/acrobat/apsb20-48.html   🛡️No.1566 CVE-2026-21643 Fortinet FortiClientEMS SQL Injection Vulnerability ✅概要 ・深刻度:9.8 Critical (CVSS Base) / NVD ・種別:SQLインジェクション (CWE-89) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Fortinet FortiClientEMSにおいて、SQLコマンドで使用される特殊要素の不適切な無効化に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたHTTPリクエストを送信されることで、SQLインジェクションを引き起こされる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・対象システムへネットワークアクセス可能 ________________________________________ ✅悪用時影響 ・任意コマンド実行 ・機密情報の漏えい、改ざん、サービス停止 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:あり(セキュリティ企業による報告) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-21643 https://www.fortiguard.com/psirt/FG-IR-26-XXX   🛡️No.1567 CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability ✅概要 ・深刻度:8.6 High (CVSS Base) / Adobe Systems Incorporated ・種別:オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染) (CWE-1321) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Adobe AcrobatおよびReaderにおいて、オブジェクトプロトタイプ属性の不適切に制御された変更に起因する脆弱性が存在。ユーザー権限で任意のコードを実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・被害者が悪意のあるファイルを開く必要がある ・対象端末でAdobe AcrobatまたはReaderが利用されている必要がある ________________________________________ ✅悪用時影響 ・現在のユーザー権限で任意コード実行 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:Adobeが悪用を確認 (Adobeヘルプセンター) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-34621 https://helpx.adobe.com/security/products/acrobat/apsb26-43.html https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post announces that CISA has confirmed exploitation of several CVEs, provides detailed technical and severity information for each, notes public PoC availability for one, and includes links to vendor patches.

    000635.7K
    43.5K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    CISA added 7 CVEs to the KEV catalog today. All confirmed active exploitation. CVE-2012-1854 — Microsoft VBA insecure library loading CVE-2020-9715 — Adobe Acrobat UAF CVE-2023-21529 — Exchange deserialization CVE-2023-36424 — Windows OOB read CVE-2025-60710 — Windows link following CVE-2026-21643 — Fortinet SQL injection CVE-2026-34621 — Adobe Acrobat prototype pollution A CVE from 2012 is still being actively exploited in 2026. Patch prioritization isn’t optional. Source: https://t.me/VulnerabilityNews/41878 → http://cisa.gov/known-exploited-vulnerabilities-catalog

    Post summary

    CISA confirmed that seven CVEs are being actively exploited across multiple vendors and vulnerability types, underscoring the urgency of patch deployment.

    11030214
    184 followersView on X
  • キタきつね@foxbook
    General

    CISAが既知の悪用された脆弱性7件をカタログに追加 CISA Adds Seven Known Exploited Vulnerabilities to Catalog #CISA (Apr 13) CVE-2012-1854 Microsoft Visual Basic for Applications のライブラリ読み込みの脆弱性 CVE-2020-9715 Adobe AcrobatのUse-After-Free脆弱性 CVE-2023-21529 Microsoft Exchange Serverにおける信頼できないデータの逆シリアル化の脆弱性 CVE-2023-36424 Microsoft Windows 境界外読み取りの脆弱性 CVE-2025-60710 Microsoft Windows リンク追跡の脆弱性 CVE-2026-21643 FortinetのSQLインジェクション脆弱性 CVE-2026-34621 Adobe AcrobatおよびReaderプロトタイプ汚染の脆弱性 https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announces the addition of seven known exploited vulnerabilities to its catalog, listing the CVEs with brief technical descriptors but without any PoC, exploit code, or patch information.

    00030341
    4.9K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Disclosure

    CVE-2023-21529 Microsoft Exchange Serverにおける信頼できないデータの逆シリアル化の脆弱性 CVE-2023-36424 Microsoft Windows 境界外読み取りの脆弱性 CVE-2025-60710 Microsoft Windows リンク追跡の脆弱性 CVE-2026-21643 FortinetのSQLインジェクション脆弱性

    Post summary

    A succinct list of four CVEs is presented with brief Japanese descriptions, but no further technical, exploitation, or mitigation information is provided.

    10000378
    40 followersView on X
  • ScyScan@ScyScan
    Active Exploitation

    Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2023-36424 #Microsoft #Windows Out-of-Bounds Read Vulnerability https://www.scyscan.com/cve-2023-36424/microsoft-windows-out-of-bounds-read-vulnerability/

    Post summary

    CVE-2023-36424, an out-of-bounds read vulnerability in Microsoft Windows, is being actively exploited in the wild.

    0000054
    61 followersView on X
  • CiberPlaneta@CiberPlanetaOrg
    Disclosure

    🛡️ CVE-2023-36424: Vulnerabilidad de Lectura Fuera de Límites en Microsoft Windows Análisis técnico de CVE-2023-36424, una falla de lectura fuera de límites en el driver CLFS de Windows que permite escalada de privilegios. Impacto, mitigacione https://www.ciberplaneta.org/vulnerabilidades/cve-2023-36424-vulnerabilidad-de-lectura-fuera-de-limites-en-microsoft-windows/ #ciberplaneta #vulnerabilidades #cve_2023_36424 #cve #vulnerabilidad #microsoft #seguridad #infosec #ciberseguridad

    Post summary

    The post announces CVE-2023-36424, a buffer‑overflow bug in the Windows CLFS driver that permits privilege escalation, and provides a brief technical analysis but no PoC, exploit, or patch information.

    0000052
    5 followersView on X
  • CiberPlaneta@CiberPlanetaOrg
    Patch

    🛡️ Alerta de Seguridad: Vulnerabilidad de Lectura Fuera de Límites en Microsoft Windows (CVE-2023-36424) El driver Common Log File System (CLFS) de Microsoft Windows presenta una vulnerabilidad de lectura fuera de límites (CWE-125) que permite escalada de privilegios local. Severidad alta (CVSS 7.8). Afecta a versiones de Windows 10 y 11. Aplicar parches urgentes según MSRC. https://www.ciberplaneta.org/boletines/84/ #ciberplaneta #bulletin #cybersecurity #cve #microsoft #windows #ioc #infosec #ciberseguridad

    Post summary

    The post alerts on CVE-2023-36424, an out‑of‑bounds read vulnerability in Windows CLFS that can lead to local privilege escalation, and urges users to apply Microsoft’s urgent patches for Windows 10 and 11.

    0000049
    5 followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--arm64
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---

Explore more