CVE-2024-30085PoC(microsoft / windows_10_1809)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1809 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2
  • windows_11_21h2

Threat summary

  • Public PoC and exploit tooling are both present
  • 14 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 12 signals
  • Technical details provided in 7 signals
  • General: 3 classified signals
  • Peaked 7d ago at 3 mentions (2026-03-04); latest day: 1
  • 14 total mentions across 8 days

Affected systems

Vendors
Products
windows_10_1809windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_11_23h2windows_server_2019windows_server_2022windows_server_2022_23h2

Deep dive

Activity timeline14 mentions / 8d
01223Mentions · 2026-03-04: 3Mentions · 2026-03-06: 1Mentions · 2026-03-31: 2Mentions · 2026-04-01: 2Mentions · 2026-04-15: 1Mentions · 2026-04-28: 2Mentions · 2026-04-29: 2Mentions · 2026-05-02: 1PoC Mentioned / Linked · 2026-03-04: 2PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-31: 2PoC Mentioned / Linked · 2026-04-01: 2PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-28: 2PoC Mentioned / Linked · 2026-04-29: 1PoC Mentioned / Linked · 2026-05-02: 1Exploit Tool / Code · 2026-03-04: 1Exploit Tool / Code · 2026-03-31: 1Exploit Tool / Code · 2026-04-01: 1Exploit Tool / Code · 2026-04-28: 1Exploit Tool / Code · 2026-05-02: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-28: 2Technical Details · 2026-04-29: 1Technical Details · 2026-05-02: 103-0403-0603-3104-0104-1504-2804-2905-02
Signal classification3 categories
PoC
642.9%
Exploit
535.7%
General
321.4%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-03-043
Exploit1General1PoC1
2026-03-061
PoC1
2026-03-312
Exploit1PoC1
2026-04-012
Exploit1General1
2026-04-151
PoC1
2026-04-282
Exploit1PoC1
2026-04-292
General1PoC1
2026-05-021
Exploit1
Full discourse14 posts
  • Alexandre Borges@ale_sp_brazil
    Exploit

    I am excited to release the seventh article in the Exploiting Reversing Series (ERS). Titled “Exploitation Techniques | CVE-2024-30085 (part 01)” this 119-page technical guide offers a comprehensive roadmap for vulnerability exploitation: https://exploitreversing.com/2026/03/04/exploiting-reversing-er-series-article-07/ Key features of this edition: [+] Dual Exploit Strategies: Two distinct exploit versions using Token Stealing and I/O Ring techniques. [+] Exploit ALPC + PreviousMode Flip + Token Stealing: elevation of privilege of a regular user to SYSTEM. [+] Exploit ALPC + Pipes + I/O Ring: elevation of privilege of a regular user to SYSTEM. [+] Solid Reliability: Two complete working and stable exploits, including an improved cleanup stage. [+] Optimized Exploit Logic: Significant refinements to the codebase and technical execution for better stability and predictability. The article guides you through the two distinct techniques for exploiting the CVE-2024-30085 Heap Buffer Overflow vulnerability. I would like to thank Ilfak Guilfanov (@ilfak on X) and Hex-Rays SA (@HexRaysSA on X) for their constant and uninterrupted support, which has helped me write these articles over time. I hope this serves as a definitive resource for your research. If you find it helpful, please feel free to share it or reach out with your feedback! Enjoy your reading and have an excellent day.

    Post summary

    The post announces a technical guide that includes two fully functional exploit versions for CVE‑2024‑30085, offering in‑depth exploitation steps and code, with no mention of patches or active use in the wild.

    685230223427.2K
    30.0K followersView on X
  • Alexandre Borges@ale_sp_brazil
    Exploit

    Exploiting Reversing (ER) series: article 09 | Exploitation Techniques: CVE-2024-30085 (part 03) Today I am releasing the nineth article in the Exploiting Reversing Series (ERS). In “Exploitation Techniques | CVE-2024-30085 (Part 09)” I provide a 106-page deep dive and a comprehensive roadmap for vulnerability exploitation: https://exploitreversing.com/2026/04/28/exploiting-reversing-er-series-article-09/ Key features of this edition: [+] Dual Exploit Strategies: Two distinct exploit editions built on the cldflt.sys heap overflow. [+] PreviousMode Edition: Exploit cldflt.sys via WNF OOB + Pipe Attributes + ALPC + _KTHREAD.PreviousMode flip: elevation of privilege of a regular user to SYSTEM. [+] PPL Bypass Edition: Exploit cldflt.sys via WNF OOB + PreviousMode flip + _EPROCESS.Protection strip + MiniDumpWriteDump: elevation of regular user to SYSTEM. [+] Solid Reliability: Two complete, stable exploits, including a multi-step cleanup phase that restores the corrupted pipe attribute Flink and _KTHREAD.PreviousMode before process exit, preventing crash on cleanup. This article guides you through two additional techniques for exploiting the CVE-2024-30085 Heap Buffer Overflow. While demonstrated here, these methods can be adapted as exploitation techniques for many other kernel targets. I hope this serves as a definitive resource for your research. If you find it helpful, please feel free to share it or reach out with your feedback! I would like to thank Ilfak Guilfanov (@ilfak) and Hex-Rays SA (@HexRaysSA) for their constant and uninterrupted support, which has been vital in helping me produce this series. The following articles will continue the miniseries about iOS and Chrome, which are my areas of research. Enjoy the reading and have an excellent day. #exploit #exploitdevelopment #windows #exploitation #vulnerability #minifilterdriver #kernel #heapoverflow

    Post summary

    The text announces a detailed article offering functional exploits for CVE‑2024‑30085, describing two stable exploit variants, method details, and cleanup steps, but does not mention active exploitation or remediation.

    35901929610.4K
    31.2K followersView on X
  • Smukx.E@5mukx
    Exploit

    Exploiting Reversing (ER) series. An step by step Exploitation Technique of Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability. (CVE-2024-30085) Link:- https://exploitreversing.com/wp-content/uploads/2026/04/exploit_reversing_09.pdf #exploit #windows https://t.co/yzRSrIOMuF

    Post summary

    A step‑by‑step exploitation technique for CVE‑2024‑30085 is published with a PDF link likely containing PoC or exploit code, but no indications of active exploitation or patching.

    2210137918.2K
    24.0K followersView on X
  • Alexandre Borges@ale_sp_brazil
    Exploit

    The eighth article of the Exploiting Reversing Series (ERS) is now live. Titled “Exploitation Techniques | CVE-2024-30085 (Part 02)” this 91-page technical guide offers a comprehensive roadmap for vulnerability exploitation: https://exploitreversing.com/2026/03/31/exploiting-reversing-er-series-article-08/ Key features of this edition: [+] Dual Exploit Strategies: Two distinct exploit versions leveraging the I/O Ring mechanism. [+] Exploit ALPC + WNF OOB + Pipe Attributes + I/O Ring: elevation of privilege of a regular user to SYSTEM. [+] Replaced ALPC one-shot write with Pipe Attribute spray for I/O Ring RegBuffers corruption: more reliable adjacency control. [+] Exploit WNF OOB + I/O Ring Read/Write: elevation of privilege of a regular user to SYSTEM. [+] Pure I/O Ring primitive: eliminated ALPC dependency entirely. WNF overflow directly corrupts I/O Ring RegBuffers for arbitrary kernel read/write. [+] Solid Reliability: Two complete, stable exploits, including an improved cleanup stage. This article guides you through two additional techniques for exploiting the CVE-2024-30085 Heap Buffer Overflow. While demonstrated here, these methods can be adapted as exploitation techniques for many other kernel targets. I would like to thank Ilfak Guilfanov (@ilfak ) and Hex-Rays SA (@HexRaysSA ) for their constant and uninterrupted support, which has been vital in helping me produce this series. I hope this serves as a definitive resource for your research. If you find it helpful, please feel free to share it or reach out with your feedback! Enjoy the read and have an excellent day. #exploit #exploitdevelopment #windows #exploitation #vulnerability #minifilterdriver #kernel #heapoverflow #ioring

    Post summary

    The post presents two stable exploitation techniques for CVE‑2024‑30085, detailing PoC code and dual I/O‑Ring based strategies, without indicating active use or available mitigations.

    5340122696.1K
    31.0K followersView on X
  • Nicolas Krassas@Dinosn
    General

    Exploiting Reversing (ER) series: article 07 | Exploitation Techniques: CVE-2024-30085 (part 01) https://exploitreversing.com/2026/03/04/exploiting-reversing-er-series-article-07/

    Post summary

    The post references a blog article on CVE‑2024‑30085 but provides no detailed exploit, PoC, patch, or vulnerability specifics.

    03010111.4K
    152.3K followersView on X
  • Nicolas Krassas@Dinosn
    General

    Exploiting Reversing (ER) series: article 08 | Exploitation Techniques: CVE-2024-30085 (part 02) https://exploitreversing.com/2026/03/31/exploiting-reversing-er-series-article-08/

    Post summary

    The text announces an article part 02 of the Exploiting Reversing series covering exploitation techniques for CVE-2024-30085, linking to a likely PoC page but providing no detailed technical or patch information.

    020981.8K
    157.2K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Exploiting Reversing (ER) series: article 09 | Exploitation Techniques: CVE-2024-30085 (part 03) https://exploitreversing.com/2026/04/28/exploiting-reversing-er-series-article-09/

    Post summary

    A link to an article is provided that presumably contains a PoC or exploitation details for CVE-2024-30085, but no evidence of active exploits, patches, or technical specifics is present in the text.

    020102971
    158.1K followersView on X
  • Mr. OS@ksg93rd
    General

    #reversing #Kernel_Security #Sec_code_review Exploiting Reversing (ER) series: Part 6 - A Deep Dive Into Exploiting a Minifilter Driver (n-day) https://exploitreversing.com/2026/02/11/exploiting-reversing-er-series-article-06/ Part 7 - Exploitation Techniques: CVE-2024-30085 (part 1) https://exploitreversing.com/2026/03/04/exploiting-reversing-er-series-article-07/ Part 8 - Exploitation Techniques: CVE-2024-30085 (part 2) https://exploitreversing.com/2026/03/31/exploiting-reversing-er-series-article-08/ Part 9 - Exploitation Techniques: CVE-2024-30085 (part 3) https://exploitreversing.com/2026/04/28/exploiting-reversing-er-series-article-09/ // This guides you through all techniques for exploiting CVE-2024-30085 Heap Buffer Overflow. These methods can be adapted as exploitation techniques for many other kernel targets ]-> Part 1-5 #reversing #Kernel_Security #Sec_code_review Exploiting Reversing (ER) series: Part 1 - Windows kernel drivers (1) https://exploitreversing.com/2023/04/11/exploiting-reversing-er-series/ Part 2 - Windows kernel drivers (2) https://exploitreversing.com/2024/01/03/exploiting-reversing-er-series-article-02/ Part 3 - Chrome https://exploitreversing.com/2025/01/22/exploiting-reversing-er-series-article-03/ Part 4 - macOS/iOS https://exploitreversing.com/2025/02/04/exploiting-reversing-er-series-article-04/ Part 5 - Hyper-V https://exploitreversing.com/2025/03/12/exploiting-reversing-er-series-article-05/

    Post summary

    The excerpt outlines a series of articles that discuss exploitation methods for CVE-2024-30085, providing the vulnerability type but no evidence of a PoC, active attacks, or patches.

    00022154
    3.3K followersView on X
  • VulnTracker@vuln_tracker
    PoC

    @ale_sp_brazil Amazing work on ERS Article 07! 119-page CVE-2024-30085 exploitation guide is exactly the deep technical education our community needs. Your step-by-step approach is invaluable.

    Post summary

    The tweet celebrates a detailed exploitation guide for CVE‑2024‑30085, indicating the availability of a proof‑of‑concept, but it provides no evidence of active exploitation, patches, or in‑depth technical details.

    10010118
    392 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 #CVE-2024-30085: From Regular User to SYSTEM – Mastering Dual Kernel Heap Overflow Exploits (106-Page Deep Dive) + Video https://undercodetesting.com/cve-2024-30085-from-regular-user-to-system-mastering-dual-kernel-heap-overflow-exploits-106-page-deep-dive-video/ Educational Purposes!

    Post summary

    The post is a comprehensive educational deep dive that includes a PoC for CVE‑2024‑30085, focusing on dual kernel heap overflow exploitation.

    0000025
    504 followersView on X
  • Jaime Andrés Restrepo 🏴‍☠️@JaimeARestrepo_
    PoC

    Últimas noticias sobre #Hacking: En las últimas 24 horas, expertos revelan técnicas avanzadas para explotar CVE-2024-30085, analizan una vulnerabilidad crítica en drivers Minifilter, y alertan sobre fallas críticas en PHP Composer que permiten ejec... 👉 https://jaimearestrepo.com/tecnicas-avanzadas-para-explotar-y-proteger-cve-2024-30085-y-otras-vulnerabilidades-criticas/

    Post summary

    The article focuses on demonstrating how to exploit CVE-2024-30085, emphasizing advanced exploitation techniques rather than offering ready‑made exploit code, mitigations, or evidence of active attacks.

    0000091
    5.3K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Exploit

    📄 New research released for CVE-2024-30085 showing dual I/O Ring-based exploit chains that combine WNF OOB, Pipe Attribute spray and kernel buffer corruption to achieve reliable local privilege escalation from regular user to SYSTEM, including arbitrary kernel read/write primitives and two stable exploitation methods. https://exploitreversing.com/2026/03/31/exploiting-reversing-er-series-article-08/

    Post summary

    The article presents dual I/O Ring exploit chains for CVE-2024-30085, detailing reliable local privilege escalation methods and stable exploitation techniques. No evidence of wild exploitation or remediation is provided.

    0000055
    813 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 Mastering the I/O Ring: A Deep Dive into #CVE-2024-30085 Exploitation Techniques + Video https://undercodetesting.com/mastering-the-i-o-ring-a-deep-dive-into-cve-2024-30085-exploitation-techniques-video/ Educational Purposes!

    Post summary

    The tweet promotes a video tutorial that demonstrates exploitation techniques for CVE‑2024‑30085, effectively sharing a proof‑of‑concept but without offering executable code or confirming widespread use.

    0000028
    452 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 #CVE-2024-30085 Exposed: Two Full Exploit Chains for #Windows Kernel Privilege Escalation + Video https://undercodetesting.com/cve-2024-30085-exposed-two-full-exploit-chains-for-windows-kernel-privilege-escalation-video/ Educational Purposes!

    Post summary

    The tweet advertises that CVE‑2024‑30085 includes two full exploit chains for Windows kernel privilege escalation and links to a video demonstrating the proof‑of‑concept, but provides no explicit code or mention of active exploitation.

    0000075
    403 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---

Explore more