NVD disclosure day

Published threat advisories for April 11, 2023

CVE advisoryKnown Exploit

CVE-2023-28252

Windows Common Log File System Driver Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Common Log File System Driver allows for privilege escalation. This could enable an attacker with local access to gain elevated permissions on affected systems, potentially impacting system integrity and data confidentiality. The exploitation of this vulnerability requires local access an

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-28229

Windows CNG Key Isolation Service Privilege Escalation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Windows CNG Key Isolation Service has a vulnerability that allows a local attacker to gain elevated privileges. This presents a business risk of unauthorized access to sensitive data and system functions, potentially leading to a complete host compromise. Organizations should identify and mitigate this risk across

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-0645

libjxl Out of Bounds Read in Exif Handler

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the libjxl image processing library may allow an attacker to cause an out-of-bounds read when processing a crafted file. This could potentially expose memory. Confirmation is needed to determine if this library is used and if it is exposed to untrusted files.