PT-2025-50155 · Microsoft · Windows
CVE-2025-62221
·
Published
2025-12-09
·
Updated
2026-07-15
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions 10 and later
Description
A use-after-free issue exists in the Windows Cloud Files Mini Filter Driver, specifically within the
cldflt.sys driver used by services such as Microsoft OneDrive. A use-after-free is a condition where a program continues to use a pointer after it has been freed, which can lead to crashes or unauthorized code execution. This flaw allows an authorized local attacker to escalate privileges to the SYSTEM level, granting full control over the affected system. This issue has been actively exploited in real-world incidents.Recommendations
Update Microsoft Windows to the December 2025 security patch level.
Fix
LPE
RCE
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows