CVE-2024-30085High· 7.8▾ MidnightPoC availableWindows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.9 · likelihood 2.9 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
15%
2 GitHub repos · Metasploit ×1
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
windows_10_1809 < 10.0.17763.5936windows_10_21h2 < 10.0.19044.4529windows_10_22h2 < 10.0.19045.4529windows_11_21h2 < 10.0.22000.3019windows_11_22h2 < 10.0.22621.3737windows_11_23h2 < 10.0.22631.3737windows_server_2019 < 10.0.17763.5936windows_server_2022 < 10.0.20348.2522windows_server_2022_23h2 < 10.0.25398.950Upgrade past the affected range:
windows_10_1809 10.0.17763.5936windows_10_21h2 10.0.19044.4529windows_10_22h2 10.0.19045.4529windows_11_21h2 10.0.22000.3019windows_11_22h2 10.0.22621.3737windows_11_23h2 10.0.22631.3737windows_server_2019 10.0.17763.5936windows_server_2022 10.0.20348.2522windows_server_2022_23h2 10.0.25398.950Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81354High· 8.2Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
CVE-2026-73017High· 7.5Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.
CVE-2026-72962High· 8.2Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69875High· 8.0Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
CVE-2026-69790High· 7.8Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally.
CVE-2026-69822High· 7.8Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.