CVE-2025-62221

9.5 CISA KEV

Microsoft · Windows

A use after free vulnerability in the Windows Cloud Files Mini Filter Driver allows a locally authenticated attacker to achieve privilege escalation.

Executive summary

This critical vulnerability in the Windows Cloud Files Mini Filter Driver is currently being exploited in the wild and enables local privilege escalation.

Vulnerability

This flaw is a use after free vulnerability located in the Windows Cloud Files Mini Filter Driver. It requires the attacker to have local access and be authenticated to the system to trigger the memory corruption, which subsequently allows for privilege escalation.

Business impact

Successful exploitation of this vulnerability allows an attacker to elevate their privileges to a higher level, potentially granting them administrative control over the compromised host. Given the CVSS score of 9.5 and the confirmation of active exploitation in the wild, the business impact is severe, posing a significant risk to the integrity and confidentiality of enterprise systems.

Remediation

Immediate Action: Apply the security updates provided in the Microsoft Security Update Guide immediately to all affected Windows endpoints.

Proactive Monitoring: Monitor system logs for suspicious process creation or unexpected behavior involving the Cloud Files Mini Filter Driver.

Compensating Controls: Ensure that endpoint protection solutions are fully updated and active to detect and block known exploit patterns associated with this CVE.

Exploitation status

Public Exploit Available: Yes, multiple public proofs of concept exist on GitHub.

Analyst recommendation

Due to the confirmed active exploitation and the critical severity of this privilege escalation flaw, organizations should prioritize patching as an emergency task. Administrators must verify that all applicable Windows versions listed are updated to the specified non-vulnerable versions to prevent unauthorized system control.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section, carried in 20 daily briefs, Dec 10 to Dec 29
  3. Analyst report written
  4. Fix documented version 10.0.17763.8146 per CVE record

Sources