CVE-2024-6768 describes a Denial of Service vulnerability in the CLFS.sys driver affecting Windows 10, 11, and Server versions 2016-2022. An authenticated low-privilege user can trigger a Blue Screen of Death, leading to system unavailability. This local attack has low complexity and high impact on system availability, as reflected by its CVSS score of 6.8 (Medium) and a high FAUCET Risk Score of 94/100. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with multiple discussions and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Microsoft | Windows 10 | 10.0.0CNA affecteddefault affected | |
| Microsoft | Windows 11 | 10.0.0CNA affecteddefault affected | |
| Microsoft | Windows Server 2016 | 10.0.0CNA affecteddefault affected | |
| Microsoft | Windows Server 2019 | 10.0.0CNA affecteddefault affected | |
| Microsoft | Windows Server 2022 | 10.0.0CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.