CVE-2024-26160
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-26160 is a newly disclosed vulnerability affecting the Windows Cloud Files Mini Filter Driver. This issue permits information disclosure, allowing an attacker to gain unauthorized access to sensitive data. By manipulating specific input, an adversary can trigger the driver to reveal details about the file system and potentially, the operating system. This vulnerability poses a significant risk, as an attacker could use the obtained information for further exploitation or reconnaissance purposes. Microsoft is currently working on a patch to address this issue, and users are encouraged to apply it as soon as it becomes available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 11 22h2
- Microsoft Windows 11 23h2
Affected Vendors
- Microsoft