LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-36424: Microsoft Windows Out-of-Bounds Read Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 13, 2026
CVSS 7.8 · High⚠ Actively exploited (CISA KEV)
7.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 27, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-36424 to its Known Exploited Vulnerabilities catalog on Apr 13, 2026, with a federal patch deadline of Apr 27, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Windows Common Log File System Driver Elevation of Privilege Vulnerability

This vulnerability is an out-of-bounds read in the Microsoft Windows Common Log File System Driver. It could allow a threat actor to escalate privileges on affected systems. The issue affects core Windows functionality, making it relevant for any organization running Microsoft Windows.

How it works

The weakness is classified as CWE-125, an out-of-bounds read. In the Common Log File System Driver, this flaw may permit a threat actor to read memory outside expected bounds, potentially leading to privilege escalation.

Attackers would need to trigger the vulnerable code path through interaction with the driver. Specific exploit mechanics are not detailed in available information and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

This affects Microsoft Windows systems that use the Common Log File System Driver. Inventory all Windows endpoints and servers in the environment.

Monitor for unusual access patterns or privilege changes that might indicate exploitation attempts. Telemetry signs of active exploitation are not specified in available information.

How to remediate

Apply the vendor-supplied update as the primary remediation step.

Additional hardening measures for out-of-bounds read issues in system drivers include restricting unnecessary access to low-level drivers where possible. Confirm exact patch details and applicability against the vendor advisory.

If you can't patch immediately

Apply mitigations according to vendor instructions. For cloud services, follow applicable BOD 22-01 guidance. Discontinue use of the product if mitigations cannot be applied.

Consider network segmentation to limit exposure of Windows systems. Monitoring for anomalous driver activity can provide additional visibility until remediation is complete.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches. Organizations can run a free exposure scan of their email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-125
CVSS base score7.8 (High)
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PublishedNov 14, 2023
Added to CISA KEVApr 13, 2026
Federal patch deadlineApr 27, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities