CVE-2026-20857

7.8

Microsoft · Windows Cloud Files Mini Filter Driver

An untrusted pointer dereference vulnerability in the Windows Cloud Files Mini Filter Driver permits a locally authenticated user to escalate privileges.

Executive summary

A local privilege escalation vulnerability in the Microsoft Windows Cloud Files Mini Filter Driver poses a significant risk to system integrity and security.

Vulnerability

The vulnerability is caused by an untrusted pointer dereference within the Cloud Files Mini Filter Driver, which can be exploited by an authenticated user with low privileges to achieve full system control.

Business impact

The exploitation of this vulnerability allows a standard local user to gain elevated privileges, potentially resulting in full system compromise. Given the CVSS score of 7.8, the vulnerability is considered High, as it enables unauthorized access to sensitive data and the ability to disable security controls, which could lead to severe organizational data breaches or long-term persistence by malicious actors.

Remediation

Immediate Action: Administrators must apply the latest security updates provided by Microsoft in the official update guide to patch the affected versions of the Windows operating system.

Proactive Monitoring: Monitor system logs for unusual process creation, specifically looking for low-privilege accounts attempting to access restricted kernel-mode components or system files.

Compensating Controls: Ensure that endpoint detection and response tools are configured to alert on unauthorized privilege escalation attempts and restrict non-administrative users from executing arbitrary code in environments where this driver is active.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations should prioritize the deployment of the relevant Microsoft security patches across all identified Windows 10 and Windows 11 endpoints. Because this vulnerability allows for local privilege escalation, failure to patch leaves systems susceptible to lateral movement and full takeover by any actor who gains initial access to a standard user account.

More Microsoft CVEs

Sources