CVE-2023-52271PoC(topazevolution / antifraud)

HIGHCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch topazevolution antifraud systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named at a later time).

7.5/ 10 priority

Sources & remediation

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • antifraud

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 2d ago at 1 mentions (2026-02-16); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
antifraud

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-16: 1Mentions · 2026-02-19: 1Mentions · 2026-06-16: 1PoC Mentioned / Linked · 2026-02-16: 1PoC Mentioned / Linked · 2026-02-19: 1Exploit Tool / Code · 2026-06-16: 1Active Exploitation · 2026-06-16: 1Patch / Workaround · 2026-06-16: 1Technical Details · 2026-02-19: 1Technical Details · 2026-06-16: 102-1602-1906-16
Signal classification3 categories
PoC
133.3%
Exploit
133.3%
Active Exploitation
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-161
PoC1
2026-02-191
Exploit1
2026-06-161
Active Exploitation1
Full discourse3 posts
  • BriPwn@BriPwn
    Exploit

    Can vulnerable drivers still kill your EDR in 2026? Spoiler: yes. 🧵 New Weekly Purple Team drops today — BYOVD using CVE-2023-52271 (wsftprm.sys), a signed driver STILL not on Microsoft's blocklist. 🔴 Attack: malicious IOCTL → ZwTerminateProcess at kernel level → EDR gone 🔵 Detect: Event ID 6, 4697, 7045, WDAC enforcement Video 👇 https://youtu.be/q6VMly9Bs5s #BYOVD #PurpleTeam #DetectionEngineering #ThreatHunting

    Post summary

    The post shares a video demonstrating how CVE‑2023‑52271 can be leveraged by sending malicious IOCTLs to ZwTerminateProcess, enabling an attacker to terminate EDR processes on a target system.

    110051214.3K
    998 followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Active Exploitation

    🚨 GÜVENLİK BÜLTENİ: DragonForce Fidye Yazılımı MS Teams Altyapısını Arka Kapı Olarak Kullanıyor (CVE-2023-52271 / CVE-2025-61155 / CVE-2025-1055) Merhaba #Brolyz Fidye yazılımı gruplarının savunma atlatma tekniklerinde kritik bir gelişme raporlandı. Symantec ve araştırmacılara göre DragonForce, Komuta ve Kontrol (C2) trafiğini gizlemek için Microsoft Teams’in TURN relay altyapısını kötüye kullanıyor. Bu yöntem özellikle #orta ve büyük ölçekli kurumların ağ güvenliğinde ciddi kör nokta oluşturuyor. 📌 Özet Saldırganlar ilk erişimi genellikle yamalanmamış MSSQL/SQL sunucuları üzerinden sağlıyor. İçeri girdikten sonra Go tabanlı özel bir arka kapı (Backdoor.Turn) yükleniyor. Bu yazılım, Microsoft kimlik servislerinden geçici Teams token’ı alarak meşru Microsoft altyapısı üzerinden QUIC tabanlı iletişim kuruyor. Böylece C2 trafiği normal MS Teams görüşmesi #gibi görünerek güvenlik katmanlarını atlatabiliyor. Ek olarak BYOVD tekniğiyle güvenlik ürünlerini devre dışı bırakma girişimleri de gözlemleniyor. ⚠️ Riskler • C2 trafiğinin MS Teams gibi meşru servislerin içine gizlenmesi • Güvenlik duvarı ve IPS sistemlerinin saldırıyı tespit edememesi • Uzun süre fark edilmeden ağ içinde kalıcılık ve yatay hareket • Veri sızdırma (Data Exfiltration) ve fidye şifreleme aşaması 🛠️ Çözüm ve Öneriler 1️⃣ Süreç Bazlı Kontrol: Yalnızca meşru teams.exe süreçlerinin Teams altyapısına erişmesine izin verin. 2️⃣ BYOVD Koruması: WDAC üzerinden Microsoft Vulnerable Driver Blocklist’i aktif edin. 3️⃣ SQL Güvenliği: İnternete açık MSSQL/SQL sunucularını kapatın ve yamalayın. 4️⃣ Threat Hunting: AD üzerinde şüpheli hesap oluşturma ve yetki yükseltme aktivitelerini analiz edin. 🔍 Unutmayın: Saldırganlar artık güvenilir bulut servislerini doğrudan gizlenme katmanı olarak kullanıyor. Sıfır Güven (Zero Trust) yaklaşımını tüm ağ mimarinize uygulamayı unutmayın. Güvenli haftalar dilerim! 🛡️

    Post summary

    The post reports active exploitation of DragonForce ransomware using Microsoft Teams’ TURN relay as a covert command‑and‑control channel tied to several CVEs, and outlines mitigation recommendations.

    01050110
    420 followersView on X
  • Viktor@vict0ni
    PoC

    BYOVD: Silencing AV/EDR with CVE-2023-52271 by me at @0x00secOfficial https://0x00sec.org/byovd-silencing-av-edr-with-cve-2023-52271/

    Post summary

    The tweet links to a blog post where the author demonstrates how CVE‑2023‑52271 can silence AV/EDR, indicating a PoC exists but no active exploitation, patch, or technical detail is provided.

    00032195
    1.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptopazevolutionantifraud---

Explore more