PT-2020-5298 · Microsoft · Windows Cloud Files Mini Filter Driver+1
CVE-2020-17103
·
Published
2020-12-08
·
Updated
2026-08-14
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows 11 (affected versions not specified)
Windows Server 2022 (affected versions not specified)
Windows Server 2025 (affected versions not specified)
Description
An elevation of privilege issue exists in the Windows Cloud Files Mini Filter Driver (
cldflt.sys), which is used for cloud storage integration and OneDrive Files On-Demand. The flaw is related to the HsmOsBlockPlaceholderAccess() function and insecure privilege management. A local attacker with low-privileged access can exploit this to elevate their privileges to NT AUTHORITYSYSTEM. The exploitation method involves modifying the windir environment variable in the registry to redirect the execution of wermgr.exe within a privileged scheduled task. Real-world attacks have been observed since April 10. Potential impacts include full host takeover, disabling of security software, credential theft via LSASS dumping, and lateral movement within the Active Directory infrastructure.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Monitor for the creation of symbolic links in the
HKEY USERS.DEFAULTSoftwarePoliciesMicrosoftCloudFilesBlockedApps registry key.
Monitor for the execution of wermgr.exe or similar system files from non-standard directories.
Track the appearance of unknown services, scheduled tasks, and drivers on the system.Exploit
LPE
DoS
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Cloud Files Mini Filter Driver