CVE-2023-28252

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 13 articles

EPSS Score

Source: FIRST.org · 2026-05-24
62.21%
probability
This CVE has a 62.21% probability of being exploited in the next 30 days.
0% Top 98.4th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Common Log File System Driver Elevation of Privilege

Attack Intelligence

Google Project Zero

Patched
April 11, 2023
Reported by
Boris Larin (oct0xor), Genwei Jiang with Mandiant, Quan Jin with DBApp Security WeBin Lab
Root Cause Analysis
https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2023/CVE-2023-28252.html

Signal Intelligence

Confidence
92%
EPSS 62.21%
Mentions 13
Last Seen May 27, 2026

CNA Information

Analyst Note

This CVE meets confirmed status criteria with strong evidence of real-world exploitation by ransomware gangs, high CVSS score (7.8), and verification from reputable security sources including Google Project Zero. The vulnerability in the Windows Common Log File System Driver represents a critical elevation of privilege vector that has been actively exploited in the wild since 2023.

Threat Actors 16

Cobalt
apt_group Financial crime 🇷🇺 RU
Harvester
apt_group Information theft and espionage Unknown
Hacking Team
apt_group 🇮🇹 IT
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
The Shadow Brokers
apt_group 🇷🇺 RU
Group 27
apt_group Information theft and espionage 🇨🇳 CN
Earth Lamia
apt_group Information theft and espionage 🇨🇳 CN
Roaming Mantis
apt_group 🇯🇵 JP
Rocke
apt_group 🇨🇳 CN
Red Dev 17
apt_group 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime
Storm-2460
apt_group 🇷🇺 RU

Triage Info

Decided atMar 03, 2026