Description
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Published: 2026-05-12
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in the Windows Cloud Files Mini Filter Driver allows a local attacker who has standard user privileges to gain higher system privileges. The vulnerability occurs when the driver frees an object while it is still in use, enabling the attacker to execute code in the driver’s context. This results in an elevation of privileges that can compromise the security of the machine.

Affected Systems

The flaw impacts Microsoft Windows 10 versions 1809, 21H2, and 22H2, Windows 11 versions 22H3, 23H2, 24H2, 25H2, and 26H1, and Windows Server 2019, 2022 (including core installations), the Server 23H2 Edition, and Server 2025. All of these operating systems include the Cloud Files Mini Filter Driver that contains the vulnerable code.

Risk and Exploitability

The CVSS score of 7.8 reflects a high‑moderate severity for local privilege escalation. While the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. The attack vector is local and requires an authorized user to trigger the use‑after‑free, so the risk is primarily to systems where the driver is active and the user can interact with the Cloud Files feature. Mitigation hinges on applying the vendor’s fix to eliminate the race condition.

Generated by OpenCVE AI on May 12, 2026 at 18:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update that addresses CVE‑2026‑34337, which resolves the use‑after‑free condition in the Cloud Files Mini Filter Driver.
  • Reboot the system after applying the update so the driver is reloaded with the corrected code.
  • If the Cloud Files feature is not required, disable it to remove the vulnerable driver from the system.

Generated by OpenCVE AI on May 12, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 May 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Title Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 26h1
Microsoft windows 11 2h2
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Microsoft windows Server 23h2
Weaknesses CWE-362
CWE-416
CPEs cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_2H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_23h2:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 26h1
Microsoft windows 11 2h2
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Microsoft windows Server 23h2
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 26h1 Windows 11 2h2 Windows Server 2019 Windows Server 2022 Windows Server 2025 Windows Server 23h2
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-05-13T03:57:06.685Z

Reserved: 2026-03-26T21:02:16.446Z

Link: CVE-2026-34337

cve-icon Vulnrichment

Updated: 2026-05-12T19:16:30.826Z

cve-icon NVD

Status : Received

Published: 2026-05-12T18:17:07.803

Modified: 2026-05-12T18:17:07.803

Link: CVE-2026-34337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T18:45:05Z

Weaknesses