Windows Cloud Files Mini Filter Driver 0-Day Vulnerability Exploited in the Wild to Escalate Privileges
ID: 4f59a57e-a91d-5b8e-99bb-b7b649641a06
STIX ID: report--4f59a57e-a91d-5b8e-99bb-b7b649641a06
Feed Name: cybersecurityNews.com
Microsoft released urgent security updates for CVE-2025-62221, a Use-After-Free flaw in the Windows Cloud Files Mini Filter (cldflt.sys) that is being actively exploited in the wild to escalate privileges to SYSTEM; affected versions include Windows 10 (including 1809), Windows 11 up to 25H2, and Windows Server 2025. Microsoft confirmed low attack complexity and functional exploit code, published KB updates on December 9, 2025, and recommends immediate patching as no workarounds are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
