CVE-2020-17103
published 2020-12-10CVE-2020-17103: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
PriorityP279high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
27.22%
97.8th percentile
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.8880 | 10.0.17763.8880 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.7219 | 10.0.22631.7219 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.8655 | 10.0.26100.8655 |
| microsoft | windows_11_version_25h2 | >= 10.0.26200.0 < 10.0.26200.8655 | 10.0.26200.8655 |
| microsoft | windows_11_version_26h1 | >= 10.0.28000.0 < 10.0.28000.2269 | 10.0.28000.2269 |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.8880 | 10.0.17763.8880 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.32995 | 10.0.26100.32995 |
| msrc | windows_10_version_1803 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1903 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_2004 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_version_1903 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor cldflt.sys (Windows Cloud Files Mini Filter Driver) for exploitation of the HsmOsBlockPlaceholderAccess routine, which is the vulnerable code path for this privilege escalation. ↗
- →Alert on unexpected SYSTEM-privileged cmd.exe processes spawned from non-interactive or unusual parent processes, as the PoC weaponizes the vulnerability to spawn a SYSTEM shell. ↗
- →The exploit is a race condition; look for repeated rapid access patterns or thread contention around Cloud Files placeholder operations as a behavioral indicator. ↗
- ·The patch issued by Microsoft in December 2020 (CVE-2020-17103) may not have fully remediated the vulnerability; the exact same issue was reported as still present on fully patched systems as of May 2026. ↗
- ·All Windows versions are likely affected; the vulnerability does not appear to be limited to a specific release, though it was reported as non-functional on the latest Windows 11 Insider Preview Canary builds. ↗
- ·The original Google Project Zero PoC works without modification, meaning publicly available exploit code is directly usable against unmitigated systems. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
vendor_msrc·2020-12-08·CVSS 7.0
CVE-2020-17103 [HIGH] Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592438
Reference: https://support.microsoft.com/help/4592438
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592446
Reference: https://support.microsoft.com/help/4592446
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592440
Reference: https://support.microsoft.com/help/4592440
Reference: https://catalog.update.microsoft
VulDB
Microsoft Windows up to Server 2019 Cloud Files Mini Filter Driver privileges management
vuldb·2026-05-17·CVSS 7.8
CVE-2020-17103 [HIGH] Microsoft Windows up to Server 2019 Cloud Files Mini Filter Driver privileges management
A vulnerability classified as critical has been found in Microsoft Windows. Impacted is an unknown function of the component Cloud Files Mini Filter Driver. The manipulation leads to improper privilege management.
This vulnerability is documented as CVE-2020-17103. The attack needs to be performed locally. There is not any exploit available.
To fix this issue, it is recommended to deploy a patch.
GHSA
GHSA-qjcx-cq93-fc22: , aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2020-17134 [HIGH] CWE-269 GHSA-qjcx-cq93-fc22: , aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'
, aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-17103, CVE-2020-17136.
GHSA
GHSA-j8pf-3vjv-773q: , aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-17103 [HIGH] CWE-269 GHSA-j8pf-3vjv-773q: , aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'
, aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-17134, CVE-2020-17136.
GHSA
GHSA-j2p5-2ggv-36cx: , aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 7.0
CVE-2020-17136 [HIGH] CWE-269 GHSA-j2p5-2ggv-36cx: , aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'
, aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-17103, CVE-2020-17134.
Project0
Hunting for Bugs in Windows Mini-Filter Drivers - Project Zero
project_zero·2021-01-01·CVSS 7.0
CVE-2018-0877 [HIGH] Hunting for Bugs in Windows Mini-Filter Drivers - Project Zero
Posted by James Forshaw, Project Zero
In December Microsoft fixed 4 issues in Windows in the Cloud Filter and Windows Overlay Filter (WOF) drivers (CVE-2020-17103, CVE-2020-17134, CVE-2020-17136, CVE-2020-17139). These 4 issues were 3 local privilege escalations and a security feature bypass, and they were all present in Windows file system filter drivers. I’ve found a number of issues in filter drivers previously, including 6 in the LUAFV driver which implements UAC file virtualization.
The purpose of a file system filter driver according to Microsoft is:
“A file system filter driver can filter I/O operations for one or more file systems or file system volumes. Depending on the nature of the driver, filter can mean log, observe, modify, or even prevent. Typical applications for file
VulnCheck
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-17103 [HIGH] Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Affected: Microsoft Windows
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.recordedfuture.com/blog/june-2026-cve-landscape
Exploit PoC: https://vulncheck.com/xdb/055ed5f957fc; https://vulncheck.com/xdb/a5f8aafb11f8; https://vulncheck.com/xdb/7342ea9e12b0
No detection rules found.
No public exploits indexed.
Hackernews
Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
blogs_hackernews·2026-06-10·CVSS 9.1
CVE-2025-10263 [CRITICAL] Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
Microsoft on Tuesday released fixes for a record 206 security vulnerabilities impacting its software portfolio, including three flaws that have been publicly disclosed at the time of release.
Of the 206 flaws, 39 are rated Critical, and 167 are rated Important in severity. This includes 63 privilege escalation, 56 remote code execution, 30 information disclosure, 27 spoofing, 20 security feature bypass, seven denial-of-service, and three tampering vulnerabilities.
The patches also include two non-Microsoft CVEs, a privilege escalation vulner
Hackernews
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
blogs_hackernews·2026-05-18·CVSS 7.8
CVE-2020-17103 [HIGH] MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma , has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems.
Codenamed MiniPlasma , the vulnerability impacts "cldflt.sys," which refers to the Windows Cloud Files Mini Filter Driver, and resides in a routine named "HsmOsBlockPlaceholderAccess." It was originally reported to Microsoft by Google Project Zero researcher James Forsha
2020-12-10
Published
Exploited in the wild