Impact
The vulnerability arises from missing authentication in a critical function of the Windows Cloud Files Mini Filter Driver. Because the driver lacks authentication checks, an attacker who is already logged in as a user with sufficient privileges can tamper with files synchronized to Cloud Files, potentially altering, deleting, or replacing data without proper authorization. This lack of authentication compromises data integrity for users who rely on the Cloud Files feature to keep local copies of cloud‑stored items.
Affected Systems
Affected systems include Microsoft Windows 10 releases 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, 26H1 (including duplicate 23H2); and Windows Server 2019 (both standard and Server Core), 2022, and 2025 (both standard and Server Core). The vulnerability applies to all processor architectures represented in the affected CPEs, such as x86, x64, and ARM64.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, and because the exploit requires an authorized local user, the likelihood of successful exploitation is limited to environments where privileged accounts are present or where privilege escalation has already occurred. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet. Nevertheless, the lack of authentication in a file‑synchronization driver warrants timely remediation.
OpenCVE Enrichment