PT-2020-5298 · Microsoft · Windows Cloud Files Mini Filter Driver+1

CVE-2020-17103

·

Published

2020-12-08

·

Updated

2026-08-14

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows 11 (affected versions not specified) Windows Server 2022 (affected versions not specified) Windows Server 2025 (affected versions not specified)
Description An elevation of privilege issue exists in the Windows Cloud Files Mini Filter Driver (cldflt.sys), which is used for cloud storage integration and OneDrive Files On-Demand. The flaw is related to the HsmOsBlockPlaceholderAccess() function and insecure privilege management. A local attacker with low-privileged access can exploit this to elevate their privileges to NT AUTHORITYSYSTEM. The exploitation method involves modifying the windir environment variable in the registry to redirect the execution of wermgr.exe within a privileged scheduled task. Real-world attacks have been observed since April 10. Potential impacts include full host takeover, disabling of security software, credential theft via LSASS dumping, and lateral movement within the Active Directory infrastructure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Monitor for the creation of symbolic links in the HKEY USERS.DEFAULTSoftwarePoliciesMicrosoftCloudFilesBlockedApps registry key. Monitor for the execution of wermgr.exe or similar system files from non-standard directories. Track the appearance of unknown services, scheduled tasks, and drivers on the system.

Exploit

LPE

DoS

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00060
CVE-2020-17103

Affected Products

Windows
Windows Cloud Files Mini Filter Driver