CVE-2020-17136

HIGH

Windows Cloud Files Mini Filter Driver - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-17136. PoCs published by cssxn, xyddnljydd.

AI-analyzed exploit summary This PoC exploits CVE-2020-17136, a local privilege escalation vulnerability in Windows Cloud Experience Host Service (CfApi). It abuses symbolic link and placeholder creation to overwrite arbitrary files, leading to EoP.

Description

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Exploits (2)

nomisec WORKING POC 11 stars
by cssxn · poc
https://github.com/cssxn/CVE-2020-17136

This PoC exploits CVE-2020-17136, a local privilege escalation vulnerability in Windows Cloud Experience Host Service (CfApi). It abuses symbolic link and placeholder creation to overwrite arbitrary files, leading to EoP.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Windows 10 (pre-patch for CVE-2020-17136)
Auth required
Prerequisites: Local access to the system · Ability to execute code with low privileges
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 3 stars
by xyddnljydd · poc
https://github.com/xyddnljydd/CVE-2020-17136

This PoC exploits CVE-2020-17136, a vulnerability in Windows Cloud Files Mini Filter Driver, by creating a mount point and using Cloud Filter API to write arbitrary data to a privileged location (e.g., C:\Windows\System32). The exploit leverages the CfExecute callback to bypass access controls.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Windows Cloud Files Mini Filter Driver (cldflt.sys)
Auth required
Prerequisites: Local access to the system · Ability to execute code with low privileges
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.1396
EPSS Percentile 96.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (26)
Microsoft/Windows 10 Version 1803 10.0.0 - publication
Microsoft/Windows 10 Version 1809 10.0.0 - publication
Microsoft/Windows 10 Version 1809 10.0.17763.0 - publication
Microsoft/Windows 10 Version 1903 for 32-bit Systems 10.0.0 - publication
Microsoft/Windows 10 Version 1903 for ARM64-based Systems 10.0.0 - publication
Microsoft/Windows 10 Version 1903 for x64-based Systems 10.0.0 - publication
Microsoft/Windows 10 Version 1909 10.0.0 - publication
Microsoft/Windows 10 Version 2004 10.0.0 - publication
Microsoft/Windows 10 Version 20H2 10.0.0 - publication
Microsoft/Windows Server 2019 10.0.17763.0 - publication
... and 16 more
Published Dec 10, 2020
Tracked Since Feb 18, 2026