Exploitation via Common Log File System

Identifies potential Common Log File System (CLFS) exploitation for privilege escalation by non-SYSTEM processes invoking CLFS log file API followed by the spawning of a child process with system privileges.

Back to all rules