Summary
Windows Cloud Files mini filter driver (cldflt.sys) mishandles a placeholder and hydration code path, allowing a local attacker to elevate privileges. Public PoC code weaponizes the original research and reports that it can spawn a SYSTEM shell on fully patched Windows systems, though reliability may vary because the trigger is race-prone. Successful exploitation gives the attacker SYSTEM-level control on the host.
Why Fix Soon?
5/6Exploitation Details
Escalate from a low-privileged local user to SYSTEM privileges on the Windows host.
Privilege EscalationAffected Software
| Product | Affected Versions |
|---|---|
| Windows | Windows 10 version 1903, 1909, 2004, and 20H2; Windows Server version 1903, 1909, 2004, and 20H2; Windows Server 2019 |
Microsoft Windows is the desktop and server operating system platform. The affected component is the Cloud Files mini filter driver (cldflt.sys), which supports cloud-backed placeholder and hydration behavior used by features such as OneDrive.
Affected ComponentCloud Files mini filter driver (cldflt.sys), especially the HsmOsBlockPlaceholderAccess path used for placeholder and hydration handling.
Cloud Files mini filter driver (cldflt.sys), especially the HsmOsBlockPlaceholderAccess path used for placeholder and hydration handling.
Not available
Not available
Install the December 2020 Windows security updates or later for the affected Windows 10 and Windows Server releases to address CVE-2020-17103.
Install the December 2020 Windows security updates or later for the affected Windows 10 and Windows Server releases to address CVE-2020-17103.
Probability of exploitation in the next 30 days
Worse than 56% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (13)
- •cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2016:20h2:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2016:1909:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2016:2004:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| msrc.microsoft.com | CVE-2020-17103 |
| projectzero.google | Hunting for Bugs in Windows Mini-Filter Drivers |
| www.bleepingcomputer.com | New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released |
| github.com | MiniPlasma |
| nvd.nist.gov | CVE-2020-17103 Detail |
| www.tenable.com | CVE-2020-17103 |
Priority History
Initial analysis