PT-2024-4174 · Microsoft · Windows Cloud Files Mini Filter Driver+1
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Cloud Files Mini Filter Driver (affected versions not specified)
Description
An elevation of privilege issue exists in the Windows Cloud Files Mini Filter Driver
cldflt.sys. The flaw is a heap-based buffer overflow that can be triggered by crafting a custom reparse point to corrupt an adjacent WNF STATE DATA object. This corruption can be leveraged to leak kernel pointers from an ALPC handle table object. Further exploitation involves a second buffer overflow to corrupt another WNF STATE DATA object and a subsequent PipeAttribute object. By forging a PipeAttribute object in userspace, an attacker can leak the token address and override privileges to escalate a regular user account to NT AUTHORITYSYSTEM. Technical exploitation strategies include the use of WNF Out-of-Bounds (OOB), ALPC, I/O Ring mechanisms, and flipping the KTHREAD.PreviousMode variable.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Cloud Files Mini Filter Driver