logo

Windows Cloud Files Mini Filter Driver 0-Day Vulnerability Exploited in the Wild to Escalate Privileges

ID: 4f59a57e-a91d-5b8e-99bb-b7b649641a06

STIX ID: report--4f59a57e-a91d-5b8e-99bb-b7b649641a06

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-10

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Microsoft released urgent security updates for CVE-2025-62221, a Use-After-Free flaw in the Windows Cloud Files Mini Filter (cldflt.sys) that is being actively exploited in the wild to escalate privileges to SYSTEM; affected versions include Windows 10 (including 1809), Windows 11 up to 25H2, and Windows Server 2025. Microsoft confirmed low attack complexity and functional exploit code, published KB updates on December 9, 2025, and recommends immediate patching as no workarounds are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.