Impact
This vulnerability is a use‑after‑free flaw in the Windows Cloud Files Mini Filter Driver. When triggered by an authorized local user, it allows the attacker to write to memory that has already been freed, resulting in an elevation of privilege that could enable the creation of privileged objects, execution of arbitrary code, or modification of system configuration. The weakness is classified as CWE‑416 and provides the malicious actor with information‑leakage and potentially persistence through re‑execution of the compromised driver. The impact is confined to the local system but can be leveraged to compromise the entire machine or domain if the account has network rights.
Affected Systems
Affected products include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Microsoft Windows Server editions 2019, 2022, and 2025. The vulnerable component is the Cloud Files Mini Filter Driver present in all listed client and server operating systems.
Risk and Exploitability
The vulnerability carries a CVSS score of 7, indicating high severity. The EPSS score is unavailable, and the issue is not currently listed in the CISA KEV catalog, suggesting it has not yet been observed in the wild. However, the local and authorized attacker requirement does not reduce the risk substantially, as many users routinely perform privileged operations that can exploit this flaw. Exploitation requires the ability to trigger the use-after-free via normal file‑system operations, implying that systems that process large numbers of Cloud Files or use automated scripts are potentially exposed.
OpenCVE Enrichment