Impact
A use‑after‑free flaw in the Windows Cloud Files Mini Filter Driver allows a local attacker who has standard user privileges to gain higher system privileges. The vulnerability occurs when the driver frees an object while it is still in use, enabling the attacker to execute code in the driver’s context. This results in an elevation of privileges that can compromise the security of the machine.
Affected Systems
The flaw impacts Microsoft Windows 10 versions 1809, 21H2, and 22H2, Windows 11 versions 22H3, 23H2, 24H2, 25H2, and 26H1, and Windows Server 2019, 2022 (including core installations), the Server 23H2 Edition, and Server 2025. All of these operating systems include the Cloud Files Mini Filter Driver that contains the vulnerable code.
Risk and Exploitability
The CVSS score of 7.8 reflects a high‑moderate severity for local privilege escalation. While the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. The attack vector is local and requires an authorized user to trigger the use‑after‑free, so the risk is primarily to systems where the driver is active and the user can interact with the Cloud Files feature. Mitigation hinges on applying the vendor’s fix to eliminate the race condition.
OpenCVE Enrichment