Impact
The vulnerability is a use‑after‑free flaw in the Windows Cloud Files Mini Filter Driver. An attacker who already has authorized local access can trigger the fault and elevate his process privileges, potentially to the level of a system or administrator account. This type of weakness is identified as CWE‑416.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server 2019, 2022, and 2025, including their Server Core editions are all affected.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. Exploitation requires physical or local access to a system that has the Cloud Files Mini Filter Driver installed. Based on the description, it is inferred that exploitation cannot be triggered over a network without such local access.
OpenCVE Enrichment