PT-2024-4174 · Microsoft · Windows Cloud Files Mini Filter Driver+1

·

CVE-2024-30085

·

Published

2024-06-11

·

Updated

2026-08-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Cloud Files Mini Filter Driver (affected versions not specified)
Description An elevation of privilege issue exists in the Windows Cloud Files Mini Filter Driver cldflt.sys. The flaw is a heap-based buffer overflow that can be triggered by crafting a custom reparse point to corrupt an adjacent WNF STATE DATA object. This corruption can be leveraged to leak kernel pointers from an ALPC handle table object. Further exploitation involves a second buffer overflow to corrupt another WNF STATE DATA object and a subsequent PipeAttribute object. By forging a PipeAttribute object in userspace, an attacker can leak the token address and override privileges to escalate a regular user account to NT AUTHORITYSYSTEM. Technical exploitation strategies include the use of WNF Out-of-Bounds (OOB), ALPC, I/O Ring mechanisms, and flipping the KTHREAD.PreviousMode variable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04659
CVE-2024-30085
ZDI-24-601

Affected Products

Windows
Windows Cloud Files Mini Filter Driver