CVE-2024-26170 is a local elevation-of-privilege vulnerability in the Windows Composite Image File System (CimFS) driver, cimfs.sys, on Windows 11. The issue was reachable because the CimFS control device lacked the FILE_DEVICE_SECURE_OPEN flag, allowing an unprivileged user to bypass the intended device access restrictions by opening child paths to the control device and issuing IOCTL requests. Researchers identified multiple bugs in the driver, and the exploited path centered on an out-of-bounds read in Cim::FileSystem::GetDataSegment. In the vulnerable logic, attacker-controlled data from a mounted CIM image could influence a branch that skipped offset bounds validation, causing the function to return success with an unvalidated offset derived from region file data. That offset was later used to read a file object pointer from memory beyond the bounds of a driver allocation, and the resulting pointer was subsequently consumed by kernel routines involved in device-object resolution and driver dispatch. By shaping paged-pool allocations and placing crafted fake objects in memory, an attacker could convert the out-of-bounds read into a controlled kernel call path and ultimately achieve privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows 11 CimFS (cimfs.sys) local privilege escalation vulnerability/bug set affecting the Composite Image File System driver, enabling unprivileged access to the driver and kernel exploitation.
An elevation-of-privilege vulnerability in Windows Composite Image File System (CimFS) patched in March 2024.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.