Netskope Threat Labs

CVE-2023-28252

ATP Sandbox Adv. HeuristicsNetskope IPS

This detection identifies exploitation attempts targeting CVE-2023-28252, which has a HIGH severity rating. Microsoft's advisory names this issue the Windows Common Log File System Driver Elevation of Privilege Vulnerability, which lets a local cyberattacker gain elevated privileges, and researchers observed exploitation in the wild.

First seen
May 2024
Last seen
October 2026
Alert Name
Win64.Exploit.CVE-2023-28252