An OOB read and write vulnerability exists in
CClfsBaseFilePersisted::ExtendMetadataBlock and CClfsBaseFilePersisted::WriteMetadataBlock when parsing a malformed BLF file. The OOB read leads to one byte increment of the rgContainers[0] value, that results pointing to a fake CONTAINER_CONTEXT with a user space address 0x5000000 treated as an object's vftable pointer, detonating the placed gadgets and escalating privilege to SYSTEM.🦠Exploit sample
⚠️The gadgets are same as the ITW exploit of CVE-2023-23376, the code layout has overlaps with the ITW exploit of CVE-2022-37969.
⚠️Exploiting the vulnerability will give a local unprivileged attacker
SYSTEM level privileges.⚠️Any authenticated local user can exploit the vulnerability and an exploit is trivial to produce.

