CVE-2023-36036
KEVmassLocal Privilege Escalation in Microsoft Windows Cloud Files Mini Filter Driver
CISA: Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability
CVE-2023-36036 is a high-severity (CVSS 7.8) elevation-of-privilege flaw caused by an out-of-bounds/heap-based buffer overflow write (CWE-122, CWE-787) in the Windows Cloud Files Mini Filter Driver, the kernel component that manages cloud-synced placeholder files (e.g., cloud storage 'files on demand' such as OneDrive). A local attacker who can already run low-privileged code on a vulnerable machine can trigger the flaw with no user interaction and escalate to SYSTEM/administrator-level privileges, enabling full control of the host and potential chaining with other vulnerabilities. The affected scope spans Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), and Windows Server 2008, 2012, 2016, and 2019, meaning the driver is present by default across essentially the entire Windows install base until patched. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-14, and it was among the three actively exploited flaws fixed in Microsoft's November 2023 Patch Tuesday; ransomware use is unknown. No public proof-of-concept is catalogued, but the EPSS probability of 16.7% (97th percentile) and the KEV listing make this a patching priority.
What to do: Apply the Microsoft November 2023 Patch Tuesday security updates (released 2023-11-14) to every in-scope Windows 10, Windows 11, and Windows Server host, prioritizing endpoints where untrusted or low-privileged users can execute code, and verify installation via Windows Update history or patch-management reporting. Per CISA's KEV required action, apply vendor mitigations or discontinue use of unpatched versions; no standalone workaround or public PoC is catalogued, so patching is the primary remediation. Because the flaw requires local access, focus early deployment on shared workstations, RDS/VDI hosts, and servers that expose interactive logon to non-administrative users.
| microsoft Windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 21H2, 22H2, 23H2 |
| microsoft Windows Server | 2008, 2012, 2016, 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-122, CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H