CVE-2024-26160

MEDIUM

Microsoft Windows 11 22h2 < 10.0.22621.3296 - Buffer Over-read

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-26160. PoCs published by CrackerCat.

AI-analyzed exploit summary This PoC exploits an information disclosure vulnerability in cldflt.sys (CVE-2024-26160) by crafting a malformed data packet to trigger a buffer overflow in CldiPortProcessGetRangeInfo, leaking kernel memory addresses. The exploit demonstrates the vulnerability by bypassing validation checks in CldiPortNotifyMessage.

Description

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

Exploits (1)

nomisec WORKING POC 3 stars
by CrackerCat · poc
https://github.com/CrackerCat/CVE-2024-26160

This PoC exploits an information disclosure vulnerability in cldflt.sys (CVE-2024-26160) by crafting a malformed data packet to trigger a buffer overflow in CldiPortProcessGetRangeInfo, leaking kernel memory addresses. The exploit demonstrates the vulnerability by bypassing validation checks in CldiPortNotifyMessage.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Complex
Reliability
Reliable
Target: Microsoft Windows 11 22H2/23H2 (cldflt.sys)
No auth needed
Prerequisites: Windows 11 22H2/23H2 with KB5034765 (unpatched) or before KB5035853
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.3812
EPSS Percentile 97.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-126
Status published
Products (3)
microsoft/windows_11_22h2 < 10.0.22621.3296
microsoft/windows_11_23h2 < 10.0.22631.3296
microsoft/windows_server_2022_23h2 < 10.0.25398.763
Published Mar 12, 2024
Tracked Since Feb 18, 2026