HIGH

CVE-2023-36036

Microsoft Windows 10 1507 2023-11-14 CVSS v3.1
CVSS
7.8
KEV

Description

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Summary dbcve.org

This is an Elevation of Privilege vulnerability in the Windows Cloud Files Mini Filter Driver. The flaw allows a local attacker to gain elevated system privileges by exploiting the way the driver handles certain operations. The CVSS 7.8 score indicates a high-severity local privilege escalation issue.

Mitigation

Apply the relevant Microsoft security update for this vulnerability through Windows Update or enterprise patch management systems. Prioritize patching systems with user-facing access where local attackers could potentially exploit this flaw.

Patch Commit

Weakness (CWE)

CWE-122 Heap-based Buffer Overflow
CWE-787 Out-of-bounds Write

EPSS Score

16.67%
Probability of exploitation in next 30 days
96.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE