PoC Archive PoC Archive

tag

Cloud-Files-Api

  • CVE-2026-41091 binary HIGH 7.8 KEV

    Microsoft Defender Link Following Local Privilege Escalation (CVE-2026-41091)

    CVE-2026-41091 is a local privilege escalation vulnerability in Microsoft Defender caused by improper link resolution (CWE-59) during file operations performed with SYSTEM privileges. By racing a Defender-triggered scan against filesystem oplocks, and then…

    Unpatched 2026-07-05
  • CVE-2026-33825 binary HIGH 7.8 KEV Ransomware

    RedSun Privileged File Write (CVE-2026-33825)

    RedSun documents a local privilege-escalation technique where Defender's handling of a cloud-tagged malicious file can be abused as a privileged file write primitive. The PoC orchestrates file operations so the antimalware rewrite path lands on a high-value…

    Patched 2026-05-15
  • CVE-2020-17103 binary HIGH 7.8 EPSS 27%

    MiniPlasma - Windows Cloud Files Mini Filter Driver LPE (CVE-2020-17103)

    MiniPlasma is a fully weaponized Windows LPE that exploits a race condition in cldflrt!HsmOsBlockPlaceholderAccess inside cldflt.sys — the same vulnerability originally discovered by James Forshaw (Google Project Zero) and reported as CVE-2020-17103 in 2020.…

    Patched 2026-05-15