ZeroHour

CVE-2023-36036

KEVmass

Local Privilege Escalation in Microsoft Windows Cloud Files Mini Filter Driver

CISA: Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
17%p97
Published
()
KEV added
AI analysis

CVE-2023-36036 is a high-severity (CVSS 7.8) elevation-of-privilege flaw caused by an out-of-bounds/heap-based buffer overflow write (CWE-122, CWE-787) in the Windows Cloud Files Mini Filter Driver, the kernel component that manages cloud-synced placeholder files (e.g., cloud storage 'files on demand' such as OneDrive). A local attacker who can already run low-privileged code on a vulnerable machine can trigger the flaw with no user interaction and escalate to SYSTEM/administrator-level privileges, enabling full control of the host and potential chaining with other vulnerabilities. The affected scope spans Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), and Windows Server 2008, 2012, 2016, and 2019, meaning the driver is present by default across essentially the entire Windows install base until patched. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-14, and it was among the three actively exploited flaws fixed in Microsoft's November 2023 Patch Tuesday; ransomware use is unknown. No public proof-of-concept is catalogued, but the EPSS probability of 16.7% (97th percentile) and the KEV listing make this a patching priority.

What to do: Apply the Microsoft November 2023 Patch Tuesday security updates (released 2023-11-14) to every in-scope Windows 10, Windows 11, and Windows Server host, prioritizing endpoints where untrusted or low-privileged users can execute code, and verify installation via Windows Update history or patch-management reporting. Per CISA's KEV required action, apply vendor mitigations or discontinue use of unpatched versions; no standalone workaround or public PoC is catalogued, so patching is the primary remediation. Because the flaw requires local access, focus early deployment on shared workstations, RDS/VDI hosts, and servers that expose interactive logon to non-administrative users.

Affected
microsoft Windows 101507, 1607, 1809, 21H2, 22H2
microsoft Windows 1121H2, 22H2, 23H2
microsoft Windows Server2008, 2012, 2016, 2019
Estimated exposure
masshundreds of millions of Windows 10/11 and Windows Server installations (order 10^8-10^9) — All in-scope Windows versions ship the Cloud Files Mini Filter Driver by default and Microsoft's Windows 10/11 install base exceeds one billion devices, so pre-patch exposure is effectively the whole Windows estate minus post-November 2023…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-122, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news