Impact
This vulnerability is a use‑after‑free flaw in the Windows Cloud Files Mini Filter Driver that permits a locally authorized user to obtain elevated privileges. By triggering the flaw, the attacker can execute privileged code and potentially compromise the system with the permissions of the user. The flaw is classified as CWE‑416, a memory safety error where a freed resource is accessed again.
Affected Systems
Affected operating systems include Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025, with both desktop and Server Core variants. The driver runs on x86, x64, and arm64 architectures as specified by the listed product SKUs.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating elevated severity for local privilege escalation. Its EPSS score of 2% denotes a moderate likelihood of exploitation, and it is not currently listed in the CISA KEV catalog. Attack requires local, authorized‑after‑free to elevate privileges.
OpenCVE Enrichment