Microsoft Windows Out-of-Bounds Read Vulnerability (CVE-2023-36424).

Release Date: 13th April 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communication and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2023-36424 is a high-severity elevation of privilege (EoP) vulnerability (CVSS 7.8) in Microsoft Windows. It affects the Windows Common Log File System (CLFS) driver, a core kernel component responsible for handling transactional logging.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2023-36424
  3. https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-36424