Impact
This vulnerability is a use‑after‑free flaw in the Windows Cloud Files Mini Filter Driver. An authorized attacker who can trigger the flaw may cause the driver to execute code with elevated privileges, enabling the attacker to gain higher‑level access on the local machine. The weakness is identified as CWE‑416, indicating improper release of a resource before its use.
Affected Systems
The flaw impacts Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server releases 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates a high severity flaw. Because the attack requires a locally authorized user to trigger the use‑after‑free condition, the EPSS score is not available, but the absence of a remote exploit vector reduces the overall threat surface. The vulnerability is not listed in the CISA KEV catalog, suggesting no large‑scale exploitation has been disclosed yet. Nevertheless, any system that accepts local user input to the Cloud Files driver remains at risk and should be patched promptly.
OpenCVE Enrichment