HomeSecurityVulnerability in Windows Cloud Files Mini Filter is being actively exploited

Vulnerability in Windows Cloud Files Mini Filter is being actively exploited

An elevation of privilege vulnerability in the Windows Cloud Files Mini Filterallows local attackers to bypass file write protections and inject malicious code into system processes.

See also: Windows systems may experience BitLocker recovery after October 2025 updates

Windows Cloud Files Mini Filter
Vulnerability in Windows Cloud Files Mini Filter is being actively exploited

Security researchers have disclosed CVE-2025-55680, a high severity privilege escalation vulnerability in the Windows Cloud Files Mini Filter driver. The vulnerability exists in the Cloud Files Filter driver's (cldsync.sys) handling of file path verification during placeholder file creation operations.

Specifically, the vulnerability is located in the call chain: HsmFltProcessHSMControl → HsmFltProcessCreatePlaceholders → HsmpOpCreatePlaceholders.

Microsoft previously patched a similar file write vulnerability reported by Project Zero in 2020. However, the current implementation contains a critical logic error. While Microsoft has added code to prevent the use of backslash characters ($$ and colon (:)) in file paths to block symbolic link attacks, the verification check can be bypassed via a Time-of-Check Time-of-Use (TOCTOU).

Attackers can modify the path string in kernel memory between the verification check and the actual file operation, allowing malicious paths to pass through security checks.

The exploitation technique requires multiple coordinated steps. First, attackers start the Remote Access Service (rasman) and create a cloud file sync root using the Cloud Files API. Then, they connect to the Cloud Files Filter driver via DeviceIoControl and establish a port to communicate with the filter manager.

See also: Microsoft Graphics Device Interface: Vulnerabilities allow code execution

Vulnerability in Windows Cloud Files Mini Filter is being actively exploited
Vulnerability in Windows Cloud Files Mini Filter is being actively exploited

The attacker then creates a thread that continuously modifies a path string in kernel memory, changing it from an innocent file name to a symbolic link pointing to system directories such as C:\Windows\System32. While one thread performs file creation operations, another thread rapidly modifies the memory location, exploiting the race condition window between the security check and the file creation.

When the synchronization is perfectly aligned, the driver creates files with elevated kernel-mode access privileges, bypassing standard access checks. Attackers exploit this by writing malicious DLLs, such as rasmxs.dll, into protected system directories. By using RPC calls to force privileged services to load the compromised library, a complete system compromise is achieved.

This vulnerability poses a serious privilege escalation risk for Windows systems. The attack requires local access to the system but offers full privilege escalation capabilities. Any authenticated user could potentially exploit this flaw to gain SYSTEM-level privileges and maintain a persistent presence via legitimate system processes.

See also: WSUS vulnerability patch broke Hotpatching in Windows Server 2025

Vulnerability in Windows Cloud Files Mini Filter is being actively exploited
Vulnerability in Windows Cloud Files Mini Filter is being actively exploited

Organizations running vulnerable versions of Windows should prioritize immediate patching, as the exploitation technique is simple and reliable.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS