Impact
The vulnerability is a heap-based buffer overflow in the Windows Cloud Files Mini Filter Driver that allows an authorized local attacker to elevate privileges. It is classified as CWE-122, meaning a flaw in memory handling can be abused to run arbitrary code with higher privileges.
Affected Systems
Affected platforms include Microsoft Windows 10 versions 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1 and 23H2; and Windows Server 2019, 2022, 2025 (both full and Server Core editions).
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is 2%, suggesting a low but non-negligible likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. A local attacker with legitimate access can trigger the overflow, potentially taking advantage of the driver's memory handling issue to gain higher privileges.
OpenCVE Enrichment