Impact
The flaw is a heap‑based buffer overflow in the Windows Cloud Files Mini Filter Driver. An attacker with local or authorized user access can trigger the overflow, enabling elevation of privileges to higher levels, potentially gaining system‑level rights on the affected machine.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2019 (including Server Core), Windows Server 2022, and Windows Server 2025 (including Server Core). All affected architectures are listed in the references and include x86, x64, and ARM64 variants.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a low exploitation probability and the vulnerability is not present in CISA’s KEV catalog. The flaw resides in a kernel‑level driver and requires only local or authorized access; if successfully exploited, it could allow an attacker to obtain higher privileges on the compromised system.
OpenCVE Enrichment