{"id":8231,"date":"2025-11-06T10:04:06","date_gmt":"2025-11-06T10:04:06","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/06\/windows-cloud-files-mini-filter-driver-vulnerability-exploited-to-escalate-privileges\/"},"modified":"2025-11-06T10:04:06","modified_gmt":"2025-11-06T10:04:06","slug":"windows-cloud-files-mini-filter-driver-vulnerability-exploited-to-escalate-privileges","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/06\/windows-cloud-files-mini-filter-driver-vulnerability-exploited-to-escalate-privileges\/","title":{"rendered":"Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges"},"content":{"rendered":"<p>    Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A privilege escalation flaw in Windows Cloud Files Mini Filter Driver has been discovered, allowing local attackers to bypass file write protections and inject malicious code into system processes.<\/p>\n<p>Security researchers have uncovered <a href=\"https:\/\/cybersecuritynews.com\/windows-cloud-files-minifilter-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-55680<\/a>, a high-severity privilege-escalation vulnerability in the Windows Cloud Files Mini Filter Driver.<\/p>\n<p>The flaw exists in the Cloud Files Filter (cldsync.sys) driver\u2019s handling of file path validation during placeholder file creation operations.<\/p>\n<p>Specifically, the vulnerability resides in the call chain: HsmFltProcessHSMControl \u2192 HsmFltProcessCreatePlaceholders \u2192 HsmpOpCreatePlaceholders.<\/p>\n<p>Microsoft previously patched a similar file write vulnerability reported by Project Zero in 2020. However, the current implementation contains a critical logical flaw.<\/p>\n<p>While Microsoft added code to prevent backslash ($$ and colon (:)) characters in file paths from being used to block symbolic link attacks, the validation check can be bypassed through a Time-of-Check Time-of-Use (TOCTOU) race condition.<\/p>\n<p>Attackers can modify the path string in kernel memory between the validation check and the actual file operation, allowing malicious paths to pass through security controls.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-the-exploit-works\"><strong>How the Exploit Works<\/strong><\/h2>\n<p>The exploitation technique requires multiple coordinated steps. First, attackers start the Remote Access Service (rasman) and create a cloud file sync root using the Cloud Files API.<\/p>\n<p>Next, they connect to the <a href=\"https:\/\/cybersecuritynews.com\/windows-cloud-files-minifilter-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cloud Files<\/a> Filter driver through DeviceIoControl calls and establish a communication port with the filter manager.<\/p>\n<p>The attacker then creates a thread that continuously modifies a path string in kernel memory, changing it from an innocent filename to a symbolic link pointing to system directories like C:WindowsSystem32.<\/p>\n<p>While one thread performs file-creation operations, another thread rapidly modifies the memory location, exploiting the race condition window between the security check and file creation.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE ID<\/th>\n<th>Vulnerability Type<\/th>\n<th>Affected Component<\/th>\n<th>CVSS Score<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2025-55680<\/td>\n<td>Privilege Escalation<\/td>\n<td>Windows Cloud Files Mini Filter Driver (cldsync.sys)<\/td>\n<td>7.8<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>When the timing aligns perfectly, the driver creates files with elevated <a href=\"https:\/\/cybersecuritynews.com\/poc-exploit-windows-kernel-mode-drivers\/\" target=\"_blank\" rel=\"noreferrer noopener\">kernel-mode<\/a> access privileges, bypassing standard access controls.<\/p>\n<p>Attackers weaponize this by writing malicious DLLs, such as rasmxs.dll, into protected system directories. Leveraging RPC calls to force privileged services to load the compromised library, resulting in complete system compromise, as <a href=\"https:\/\/ssd-disclosure.com\/cloud-filter-arbitrary-file-creation-eop-patch-bypass-lpe\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported<\/a> by ssd-disclosure.<\/p>\n<p>This vulnerability represents a serious <a href=\"https:\/\/cybersecuritynews.com\/windows-cloud-files-minifilter-vulnerability\/\">privilege escalation<\/a> risk for Windows systems. The attack requires local system access but delivers complete privilege escalation capabilities.<\/p>\n<p>Any authenticated user can potentially exploit this flaw to gain SYSTEM-level privileges and maintain persistence through<a href=\"https:\/\/cybersecuritynews.com\/hackers-use-legitimate-drivers-to-kill-antivirus\/\" target=\"_blank\" rel=\"noreferrer noopener\"> legitimate system <\/a>processes.<\/p>\n<p>Organizations running vulnerable Windows versions should prioritize patching immediately, as the exploitation technique is straightforward and reliable.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/windows-cloud-files-vulnerability-exploited\/\">Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/windows-cloud-files-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges A privilege escalation flaw in Windows Cloud Files Mini Filter Driver has been discovered, allowing local attackers to bypass file write protections and inject malicious code into system processes. Security researchers have uncovered CVE-2025-55680, a high-severity privilege-escalation vulnerability in the Windows Cloud Files Mini [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-8231","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8231"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8231"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8231\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}