logo

Finding vulnerabilities in ClipSp, the driver at the core of Windows’ Client License Platform

ID: 12f38363-e415-5d55-862d-3147017b59fd

STIX ID: report--12f38363-e415-5d55-862d-3147017b59fd

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2024-11-25

Date Updated: 2026-04-27

Author: Philippe Laulheret

...
...

Cisco Talos researchers examined the obfuscated Microsoft ClipSp (clipsp.sys) driver used for licensing and system policies on Windows 10/11, deobfuscated it (Warbird obfuscation), and discovered eight vulnerabilities — including signature bypasses, TLV parsing flaws, out-of-bounds reads/writes, and race conditions — that can enable privilege escalation and LPAC sandbox escape; the report includes analysis of driver interfaces, license formats, exploitation primitives, and a PoC-level discussion of exploitation challenges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.