Impact
A heap-based buffer overflow in the Windows Cloud Files Mini Filter Driver allows an authorized attacker who can inject data into the driver to gain higher privileges on a local system. This flaw, identified as CWE‑122, permits elevation of privileges rather than arbitrary code execution, making it a high‑risk local escalation vector.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2 and 22H2; Windows 11 versions 22H3, 23H2, 24H2 and 25H2; Windows Server 2019; Windows Server 2022; Windows Server 2025, including all Server Core installations. All listed x86, x64, and ARM64 builds are affected.
Risk and Exploitability
The CVSS score of 7.8 quantifies this as a high‑severity flaw, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local access and the ability to interact with the Cloud Files service to trigger the overflow, making the attack vector local and privilege dependent.
OpenCVE Enrichment