Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability
Vulnerability
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been identified in the Windows Cloud Files Mini Filter Driver. This vulnerability allows an authorized attacker to locally elevate privileges. The issue arises from a race condition where the timing of events can be manipulated, potentially leading to unauthorized access or control.
Impact
Exploitation of this vulnerability could allow a domain user to elevate privileges to the SYSTEM integrity level.
Remediation
Users can apply the security update KB5066835 to address this vulnerability. This security update is available through the Microsoft Update Catalog. For Windows Server 2022, 23H2 Edition (Server Core installation), the security update is KB5066780. For Windows Server 2019, the security update is KB5066586.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
