KEV · Actively exploited
CVE-2023-36424
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability
EPSS
11.20%
moderate exploit risk
percentile 93.6%
CISA Known Exploited Vulnerability
- Added to KEV
- 2026-04-13
- Remediation deadline
- 2026-04-27
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware
- No
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Fixed in Windows Server 2022 (Server Core installation) 10.0.20348.2113 Windows Server 2022 10.0.25398.531 Windows Server 2019 (Server Core installation) 10.0.17763.5122 Windows Server 2019 10.0.17763.5122 Windows Server 2016 (Server Core installation) 10.0.14393.6452 Windows Server 2016 10.0.14393.6452 Windows 11 23H2 · 2023-H2 10.0.22631.2715 Windows 11 22H2 · 2022-H2 10.0.22621.2715 Windows 11 21H2 · 2021-H2 10.0.22000.2600 Windows 10 22H2 · 2022-H2 10.0.19045.3693 Windows 10 21H2 · 2021-H2 10.0.19043.3693 Windows 10 1809 · 2018-09 10.0.17763.5122 Windows 10 1607 · 2016-07 10.0.14393.6452