PT-2024-4174 · Microsoft · Windows Cloud Files Mini Filter Driver+1
Alex Birnberg
+4
·
Published
2024-06-11
·
Updated
2026-04-01
·
CVE-2024-30085
CVSS v3.1
7.8
High
| AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to June 2024 Patch Tuesday
Description
The issue is a heap-based buffer overflow vulnerability affecting the Windows Cloud Files Mini Filter Driver (
cldflt.sys). Successful exploitation allows an attacker to elevate privileges to the NT AUTHORITYSYSTEM level. The vulnerability exists due to improper handling of reparse points, potentially corrupting adjacent WNF STATE DATA objects and leaking kernel pointers via ALPC handle tables. Exploitation involves corrupting PipeAttribute objects to leak token addresses and override privileges. A proof-of-concept exploit is publicly available.API Endpoints: Not specified
Vulnerable Parameters or Variables:
reparse point, WNF STATE DATA, PipeAttribute
Function Names: Not specifiedRecommendations
Apply updates released during the June 2024 Patch Tuesday to address the vulnerability.
Exploit
Fix
LPE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Cloud Files Mini Filter Driver