Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability

Vulnerability

A heap-based buffer overflow vulnerability has been identified in the Windows Cloud Files Mini Filter Driver. This vulnerability allows an authorized attacker to locally elevate privileges. The issue affects multiple Windows versions, including various editions of Windows 10, Windows 11, Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2022, and several others. The vulnerability arises from an untrusted pointer dereference, leading to a buffer overflow that can be exploited to gain higher privileges, potentially up to SYSTEM rights.

Impact

Exploitation of this vulnerability could allow an authorized user to gain elevated privileges, with the potential to acquire SYSTEM rights.

Remediation

Users can apply the security updates provided by Microsoft to address this vulnerability. These security updates are available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles linked within the update guide.

Added: Jan 13, 2026, 7:16 PM
Updated: Jan 13, 2026, 7:16 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
3.3
remediation
7.7
relevance
2.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.