CVE-2023-28252
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
13 articles
EPSS Score
Source: FIRST.org · 2026-05-24
62.21%
probability
This CVE has a 62.21% probability
of being exploited in the next 30 days.
0%
Top 98.4th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroCommon Log File System Driver Elevation of Privilege
Attack Intelligence
Google Project Zero
Patched
April 11, 2023
Reported by
Boris Larin (oct0xor), Genwei Jiang with Mandiant, Quan Jin with DBApp Security WeBin Lab
Root Cause Analysis
https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2023/CVE-2023-28252.html
2023 Threat Landscape Year in Review: If Everything Is Critical, Nothing Is
Qualys
Dec 19, 2023
Windows zero-day vulnerability exploited in ransomware attacks
BleepingComputer
Apr 11, 2023
Defense Lessons From the Black Basta Ransomware Playbook
Qualys
Feb 25, 2025
Microsoft and Adobe Patch Tuesday April 2023 Security Update Review
Qualys
Apr 12, 2023
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable-Research
May 27, 2026
Microsoft: Windows CLFS zero-day exploited by ransomware gang
BleepingComputer
Apr 08, 2025
Microsoft patches Windows Kernel zero-day exploited since 2023
BleepingComputer
Mar 12, 2025
Microsoft April 2023 Patch Tuesday fixes 1 zero-day, 97 flaws
BleepingComputer
Apr 11, 2023
Signal Intelligence
Confidence
92%
EPSS
62.21%
Mentions
13
Last Seen
May 27, 2026
CNA Information
Analyst Note
This CVE meets confirmed status criteria with strong evidence of real-world exploitation by ransomware gangs, high CVSS score (7.8), and verification from reputable security sources including Google Project Zero. The vulnerability in the Windows Common Log File System Driver represents a critical elevation of privilege vector that has been actively exploited in the wild since 2023.
Threat Actors 16
Cobalt
apt_group
Financial crime
🇷🇺 RU
Harvester
apt_group
Information theft and espionage
Unknown
Hacking Team
apt_group
🇮🇹 IT
SCATTERED SPIDER
apt_group
Financial crime
🇺🇸 US
The Shadow Brokers
apt_group
🇷🇺 RU
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
Earth Lamia
apt_group
Information theft and espionage
🇨🇳 CN
Roaming Mantis
apt_group
🇯🇵 JP
Rocke
apt_group
🇨🇳 CN
Red Dev 17
apt_group
🇨🇳 CN
Red October
apt_group
🇷🇺 RU
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Operation Shadow Force
apt_group
🇨🇳 CN
Operation Black Atlas
apt_group
Financial crime
Storm-2460
apt_group
🇷🇺 RU
Triage Info
Decided atMar 03, 2026