CVE-2024-26160
MEDIUMMicrosoft Windows 11 22h2 < 10.0.22621.3296 - Buffer Over-read
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2024-26160. PoCs published by CrackerCat.
AI-analyzed exploit summary This PoC exploits an information disclosure vulnerability in cldflt.sys (CVE-2024-26160) by crafting a malformed data packet to trigger a buffer overflow in CldiPortProcessGetRangeInfo, leaking kernel memory addresses. The exploit demonstrates the vulnerability by bypassing validation checks in CldiPortNotifyMessage.
Description
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
Exploits (1)
This PoC exploits an information disclosure vulnerability in cldflt.sys (CVE-2024-26160) by crafting a malformed data packet to trigger a buffer overflow in CldiPortProcessGetRangeInfo, leaking kernel memory addresses. The exploit demonstrates the vulnerability by bypassing validation checks in CldiPortNotifyMessage.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N