[ << ALL_FEED ]

Roots of the CVE-2024-30085 vulnerability

More in Windows

Roots of the CVE-2024-30085 Vulnerability 🌳

Back in September of last year, we at ESC-VR successfully reproduced an exploit for CVE-2024-30085 — a vulnerability in the Windows Cloud Files Mini Filter subsystem. The subsystem’s code resides in cldflt.sys — it is a minifilter driver, and it belongs to the preinstalled client of the Microsoft OneDrive cloud service.

Using the vulnerability and a WNF + ALPC chain, we created primitives for reading from and writing to kernel memory. Thanks to this, we stole a system token and launched a terminal with NT AUTHORITY\SYSTEM privileges.

🧐 Recently, as a follow-up to the publication, we released a detailed analysis of the CVE-2024-30085 vulnerability and the techniques applicable during kernel heap exploitation on Windows 10 22H2 19045.3803.

Read the analysis in the blog on Habr.

#escvr #cve #win
@ptescalator

More from author_vr

More from author_vr

More in Windows