A privilege escalation vulnerability exists in the CLFS.sys ValidateRegionBlocks functionality of Microsoft Windows 10. A malformed log file could cause a pool overflow, and an adversary could gain the ability to execute code on the victim machine. Microsoft disclosed and patched this bug as part of their monthly security update Tuesday. The following SNORT.org rules will detect exploitation attempts, and current rules are subject to change pending additional vulnerability information. An attacker can trigger this bug from userland using a malicious log file.”]
Source: https://blog.talosintelligence.com/2020/09/vuln-spotlight-windows-10-clfs-sept-2020.html

