← back
CVE-2023-36036

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 16.5%● KEVCWE-122
In short

A flaw in Windows Cloud Files Mini Filter Driver allows an attacker with local access to run code with higher privileges than their account normally permits. This is dangerous because it can let an attacker take full control of a computer.

Technical detail

A privilege escalation vulnerability exists in the Windows Cloud Files Mini Filter Driver (CWE-122: heap buffer overflow) that can be exploited by a local authenticated attacker to execute arbitrary code with SYSTEM privileges. The vulnerability requires local code execution context but does not require additional user interaction.

Summary generated and translated by AI from the official description.
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →