CVE-2023-35355 is an Elevation of Privilege vulnerability in the Windows Cloud Files Mini Filter Driver, affecting multiple versions of Windows 10, 11, and Server. With a CVSS score of 7.8 (High), it allows a local, low-privileged attacker to achieve high impact on confidentiality, integrity, and availability without user interaction. While not currently listed on CISA's KEV catalog, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and community discussion and media coverage are minimal, suggesting limited current exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.4851CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* | ||
< 10.0.19044.3448CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.3448CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22000.2416CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.22621.2275CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.