Record summary

CVE-2020-17136 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

, aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-17103, CVE-2020-17134.

Description source: GitHub Advisory

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Affected products and versions

Showing 12 of 14
ProductSourceVersion rangeStatus
CVE List10.0.0 to < publicationaffected
CVE List10.0.17763.0 to < publicationaffected
10.0.0 to < publicationaffected

Windows 10 Version 1903 for 32-bit Systems

Browse Microsoft / Windows 10 Version 1903 for 32-bit Systems
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for ARM64-based Systems

Browse Microsoft / Windows 10 Version 1903 for ARM64-based Systems
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for x64-based Systems

Browse Microsoft / Windows 10 Version 1903 for x64-based Systems
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.17763.0 to < publicationaffected

Windows Server 2019 (Server Core installation)

Browse Microsoft / Windows Server 2019 (Server Core installation)
CVE List10.0.17763.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected

Proofs of concept

2

Catalogued exploits

MetasploitCVE-2020-1170 Cloud Filter Arbitrary File Creation EOPMetasploit exploitby Grant Willcox +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

Repository PoCs

GitHubcssxn/CVE-2020-17136Repository PoCby cssxnStars: 10Not analyzed6 files

22.7 KiB

GitHub

PoC details

References

3