CVE-2025-62457

7.8

Microsoft · Windows

An out-of-bounds read vulnerability in the Windows Cloud Files Mini Filter Driver allows a locally authenticated attacker to elevate privileges on the target system.

Executive summary

A critical privilege escalation vulnerability in the Microsoft Windows Cloud Files Mini Filter Driver allows authorized local attackers to gain elevated system permissions.

Vulnerability

This flaw is an out-of-bounds read (CWE-125) occurring within the Cloud Files Mini Filter Driver. It requires the attacker to possess local authenticated access to the system to trigger the vulnerability.

Business impact

Successful exploitation allows an attacker to elevate privileges locally, which may lead to full system compromise. Given the CVSS score of 7.8, this vulnerability poses a significant risk to organizational integrity, as it grants attackers the ability to bypass standard security controls and execute unauthorized code with higher authority.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to patch the vulnerable driver.

Proactive Monitoring: Monitor system logs for unusual process creation or unauthorized attempts to interact with the Cloud Files Mini Filter Driver.

Compensating Controls: Ensure endpoint detection and response tools are active to identify and block suspicious local privilege escalation attempts.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations should prioritize the deployment of the provided Microsoft security updates to all affected Windows endpoints. Because this vulnerability enables privilege escalation, it is essential to patch systems promptly to prevent attackers from gaining elevated control over compromised machines.

More Microsoft CVEs

Sources