Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges

Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges

Posted on November 5, 2025November 5, 2025 By CWS

A privilege escalation flaw in Home windows Cloud Information Mini Filter Driver has been found, permitting native attackers to bypass file write protections and inject malicious code into system processes.

Safety researchers have uncovered CVE-2025-55680, a high-severity privilege-escalation vulnerability within the Home windows Cloud Information Mini Filter Driver.

The flaw exists within the Cloud Information Filter (cldsync.sys) driver’s dealing with of file path validation throughout placeholder file creation operations.

Particularly, the vulnerability resides within the name chain: HsmFltProcessHSMControl → HsmFltProcessCreatePlaceholders → HsmpOpCreatePlaceholders.

Microsoft beforehand patched an identical file write vulnerability reported by Challenge Zero in 2020. Nevertheless, the present implementation incorporates a important logical flaw.

Whereas Microsoft added code to forestall backslash ($$ and colon (:)) characters in file paths from getting used to dam symbolic hyperlink assaults, the validation verify may be bypassed by way of a Time-of-Examine Time-of-Use (TOCTOU) race situation.

Attackers can modify the trail string in kernel reminiscence between the validation verify and the precise file operation, permitting malicious paths to cross by way of safety controls.

How the Exploit Works

The exploitation method requires a number of coordinated steps. First, attackers begin the Distant Entry Service (rasman) and create a cloud file sync root utilizing the Cloud Information API.

Subsequent, they hook up with the Cloud Information Filter driver by way of DeviceIoControl calls and set up a communication port with the filter supervisor.

The attacker then creates a thread that repeatedly modifies a path string in kernel reminiscence, altering it from an harmless filename to a symbolic hyperlink pointing to system directories like C:WindowsSystem32.

Whereas one thread performs file-creation operations, one other thread quickly modifies the reminiscence location, exploiting the race situation window between the safety verify and file creation.

CVE IDVulnerability TypeAffected ComponentCVSS ScoreCVE-2025-55680Privilege EscalationWindows Cloud Information Mini Filter Driver (cldsync.sys)7.8

When the timing aligns completely, the driving force creates recordsdata with elevated kernel-mode entry privileges, bypassing customary entry controls.

Attackers weaponize this by writing malicious DLLs, resembling rasmxs.dll, into protected system directories. Leveraging RPC calls to pressure privileged companies to load the compromised library, leading to full system compromise, as reported by ssd-disclosure.

This vulnerability represents a critical privilege escalation danger for Home windows methods. The assault requires native system entry however delivers full privilege escalation capabilities.

Any authenticated person can probably exploit this flaw to achieve SYSTEM-level privileges and preserve persistence by way of professional system processes.

Organizations working weak Home windows variations ought to prioritize patching instantly, because the exploitation method is simple and dependable.

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Cloud, Driver, Escalate, Exploited, Files, Filter, Mini, Privileges, Vulnerability, Windows

Post navigation

Previous Post: October Sees Rise in Phishing and Ransomware Attacks, Including TyKit and Google Careers Scams
Next Post: Ransomware Attack on European Organizations Surge as Hackers Leveraging AI-Tools for Attacks

Related Posts

Aembit Enhances IAM for Microsoft’s Copilot Studio Aembit Enhances IAM for Microsoft’s Copilot Studio Cyber Security News
Apache bRPC Vulnerability Enables Remote Command Injection Apache bRPC Vulnerability Enables Remote Command Injection Cyber Security News
Nx Console Extension Breach: Developer Secrets at Risk Nx Console Extension Breach: Developer Secrets at Risk Cyber Security News
Windows 11 Update to Block Untrusted Kernel Drivers Windows 11 Update to Block Untrusted Kernel Drivers Cyber Security News
Microsoft Patches Wormable RCE Vulnerability in Windows and Windows Server Microsoft Patches Wormable RCE Vulnerability in Windows and Windows Server Cyber Security News
Akira Ransomware Targets Over 250 Organizations, Extracts  Million in Ransom Payments – New CISA Report Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments – New CISA Report Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark