Impact
The vulnerability is a use‑after‑free flaw in the Windows Cloud Files Mini Filter Driver that allows an authorized local attacker to execute privileged code and elevate privileges. The weakness aligns with CWE‑416 and can be triggered through legitimate user activity on the infected system.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2 and 22H2; Windows 11 versions 22H3, 23H2, 24H2 and 25H2; Windows Server 2019, 2022 and 2025, including Server Core installations. All affected releases run on x86, x64 and arm64 architectures.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity. An EPSS score of 2 % indicates a measurable probability of exploitation, and the vulnerability is listed in the CISA KEV catalog, confirming it is being exploited in the wild. Exploitation requires an authenticated local user, meaning an attacker must be physically present or otherwise logged on to the target machine.
OpenCVE Enrichment