CVE-2025-62221High· 7.8▾ Abyssal⚠ Exploited in the wild0dayPoC availableUse after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 0.5 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Dec 30, 2025
Last analysed / modified upstream
2.5%
1 GitHub repo (last check)
Added to the CISA catalog on Dec 9, 2025. Federal remediation due Dec 30, 2025. View catalog ↗
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
windows_10_1809 < 10.0.17763.8146windows_10_21h2 < 10.0.19044.6691windows_10_22h2 < 10.0.19045.6691windows_11_23h2 < 10.0.22631.6345windows_11_24h2 < 10.0.26100.7392windows_11_25h2 < 10.0.26200.7392windows_server_2019 < 10.0.17763.8146windows_server_2022 < 10.0.20348.4467windows_server_2022_23h2 < 10.0.25398.2025windows_server_2025 < 10.0.26100.7392Upgrade past the affected range:
windows_10_1809 10.0.17763.8146windows_10_21h2 10.0.19044.6691windows_10_22h2 10.0.19045.6691windows_11_23h2 10.0.22631.6345windows_11_24h2 10.0.26100.7392windows_11_25h2 10.0.26200.7392windows_server_2019 10.0.17763.8146windows_server_2022 10.0.20348.4467windows_server_2022_23h2 10.0.25398.2025windows_server_2025 10.0.26100.7392Connected by shared product, vendor, weakness, or advisory.
CVE-2021-34486High· 7.8Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2024-30089High· 7.8Microsoft Streaming Service Elevation of Privilege Vulnerability
CVE-2022-21882High· 7.0Win32k Elevation of Privilege Vulnerability
CVE-2021-36934High· 7.8An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database
CVE-2024-21338High· 7.8Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-80093High· 7.0Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.