Impact
A use‑after‑free flaw exists in the Windows Cloud Files Mini Filter driver that allows a user who already has local, authorized access to manipulate memory after the driver deallocates it. This condition can be exploited to execute code with elevated privileges, resulting in the compromise of the entire operating system. The core weakness is categorized as CWE‑416: Use After Free.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; Windows Server 2019 (incl. Server Core), 2022, and 2025 (incl. Server Core).
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate severity vulnerability. An EPSS score of less than 1 % suggests that exploitation opportunities are currently rare, and the vulnerability is not listed in the CISA KEV catalog. Attackers require local, authorized access, implying a local attack vector, but once reached they can gain system‑level privileges.
OpenCVE Enrichment