Summary:
The Windows Common Log File System (CLFS) includes a zero-day vulnerability that Microsoft has patched. Cybercriminals are actively using this vulnerability to gain elevated privileges and distribute Nokoyawa ransomware payloads. The CVE-2023-28252 Windows zero-day vulnerability was also added to CISA's list of known exploited vulnerabilities due to its continuous exploitation. It can be exploited by local attackers in low-complexity attacks without user input, and it affects every supported version of Windows server and client. Through successful exploitation, threat actors can fully compromise targeted Windows computers by obtaining SYSTEM rights. According to security researchers, Recent Nokoyawa attacks involving ransomware were found to use the CVE-2023-28252 vulnerability. Researchers found the vulnerability on Microsoft Windows servers belonging to various small and medium-sized businesses in the Middle Eastern and North American regions.[/subscribe_to_unlock_form]
Summary:
The Windows Common Log File System (CLFS) includes a zero-day vulnerability that Microsoft has patched. Cybercriminals are actively using this vulnerability to gain elevated privileges and distribute Nokoyawa ransomware payloads. The CVE-2023-28252 Windows zero-day vulnerability was also added to CISA's list of known exploited vulnerabilities due to its continuous exploitation. It can be exploited by local attackers in low-complexity attacks without user input, and it affects every supported version of Windows server and client. Through successful exploitation, threat actors can fully compromise targeted Windows computers by obtaining SYSTEM rights. According to security researchers, Recent Nokoyawa attacks involving ransomware were found to use the CVE-2023-28252 vulnerability. Researchers found the vulnerability on Microsoft Windows servers belonging to various small and medium-sized businesses in the Middle Eastern and North American regions.[emaillocker id="1283"]
The first known attempt by cybercriminals to use a more recent version of Nokoyawa ransomware was attacking CVE-2023-28252. Researchers claim that since June 2022, the Nokoyawa ransomware group has employed additional exploits that target the Common Log File System (CLFS) driver. These attacks share a number of characteristics with the Nokoyawa variant while also being distinctively different, tying them all to a single exploit creator. The group has exploited at least five other CLFS exploits to target a variety of business sectors, including but not limited to software development, energy, manufacturing, retail and wholesale, and the energy industry.
The Nokoyawa ransomware first appeared in February 2022 as a strain that could target 64-bit Windows-based computers in double extortion attempts. In these attacks, threat actors take confidential data from infected networks and threaten to publish it online if a ransom is not paid. the Nokoyawa ransomware has been rewritten in Rust as opposed to the original version, which was created using the C programming language. It shares code with the JSWorm, Karma, and Nemty ransomware. Early versions of Nokoyawa were simply JSWorm ransomware that had been "rebranded."
Cybercriminals employed a more recent version of Nokoyawa in this attack, which is substantially different from the JSWorm codebase. According to researchers, cybercrime organizations are deploying more complex zero-day exploits in their attacks. In the past, Advanced Persistent Threat actors (APTs) mainly used it as a tool, but now cybercriminals have the ability to acquire zero days and regularly employ them in attacks.
Recommendations:
We strongly recommend you download and install the security update for CLFS.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]