PT-2024-4174 · Microsoft · Windows Cloud Files Mini Filter Driver+1

Alex Birnberg

+4

·

Published

2024-06-11

·

Updated

2026-04-01

·

CVE-2024-30085

CVSS v3.1

7.8

High

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to June 2024 Patch Tuesday
Description The issue is a heap-based buffer overflow vulnerability affecting the Windows Cloud Files Mini Filter Driver (cldflt.sys). Successful exploitation allows an attacker to elevate privileges to the NT AUTHORITYSYSTEM level. The vulnerability exists due to improper handling of reparse points, potentially corrupting adjacent WNF STATE DATA objects and leaking kernel pointers via ALPC handle tables. Exploitation involves corrupting PipeAttribute objects to leak token addresses and override privileges. A proof-of-concept exploit is publicly available.
API Endpoints: Not specified Vulnerable Parameters or Variables: reparse point, WNF STATE DATA, PipeAttribute Function Names: Not specified
Recommendations Apply updates released during the June 2024 Patch Tuesday to address the vulnerability.

Exploit

Fix

LPE

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-04659
CVE-2024-30085
ZDI-24-601

Affected Products

Windows
Windows Cloud Files Mini Filter Driver