CVE-2020-17136 is an elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys), specifically in the CfCreatePlaceholders API. The vulnerability arises from improper access checks when creating files and directories, due to the use of FltCreateFileEx with KernelMode access and insufficient path validation. This allows non-administrative users to create or overwrite files in protected locations such as ProgramData, potentially leading to privilege escalation or system compromise. The vulnerability affects Windows 10 version 2004 and was reported by James Forshaw of Google Project Zero.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (modules/exploits/windows/local/cve_2020_17136.rb) that exploits CVE-2020-17136, a privilege escalation vulnerability in the Windows Cloud Filter driver (cldflt.sys) on Windows 10 v1803 and later (prior to December 2020 updates). The exploit abuses improper access checks in the driver to create files in protected directories with KernelMode permissions, enabling a DLL hijacking attack against the Microsoft Storage Spaces SMP service. Successful exploitation grants code execution as NETWORK SERVICE, which can be further escalated to SYSTEM using Meterpreter's getsystem command. The module supports customizable payloads (defaulting to Meterpreter reverse shell), AMSI and ETW bypass, and process cleanup options. The code is written in Ruby and is fully integrated into the Metasploit framework, making it weaponized and easy to use for post-exploitation privilege escalation on vulnerable Windows systems.
This repository contains a Visual Studio C++ project implementing a proof-of-concept (POC) exploit for CVE-2020-17136, a local privilege escalation vulnerability in Microsoft Windows 10's Cloud Filter API (cfapi). The main code file, CVE_2020_17136.cpp, demonstrates how an attacker with local access can abuse the Cloud Filter API to create arbitrary files in protected locations by registering a sync root, creating a directory junction, and using placeholder file creation. The exploit attempts to copy an attacker-controlled file (1.exe) from a writable temp directory to a protected path (C:\Windows\system32\test\aaa.exe) via a crafted junction (symbol_c). The exploit is a POC and does not include a malicious payload; it is intended to demonstrate the vulnerability. The repository structure is typical for a Visual Studio C++ project, with solution and project files, and a single C++ source file containing the exploit logic. No network or remote attack vectors are present; the exploit is purely local and targets Windows 10 systems vulnerable to CVE-2020-17136.
This repository is a C++ proof-of-concept exploit for CVE-2020-17136, a privilege escalation vulnerability in Microsoft Windows Installer. The solution consists of two main Visual Studio projects: 'CVE-2020-17136' (the exploit) and 'CommonUtils' (a utility library). The codebase provides a comprehensive set of utilities for creating and manipulating Windows file, directory, and registry symbolic links and hardlinks, as well as handling reparse points and object directories. The exploit leverages these primitives to perform symlink attacks against privileged Windows Installer operations, potentially allowing a local attacker to escalate privileges to SYSTEM. The code is modular, with clear separation between exploit logic and reusable utilities. No network endpoints are present; all attack vectors are local, targeting the Windows file system and registry. The README references public advisories and Metasploit discussions, confirming the exploit's purpose and target. The main entry point is likely 'CVE-2020-17136/main.cpp', which would orchestrate the attack using the provided utilities.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.