CVE-2025-62221
HIGH KEVWindows Cloud Files Mini Filter Driver - Use-After-Free
Title source: llmExploitation Summary
CVE-2025-62221 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added December 9, 2025. EIP tracks 1 public exploit from researchers including Teodor1231241.
AI-analyzed exploit summary This repository contains a Proof-of-Concept (PoC) for CVE-2025-62221, a Use-After-Free (UAF) vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys). The exploit demonstrates a privilege escalation from user-mode to NT AUTHORITY\SYSTEM by manipulating memory objects through a race condition.
Description
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Exploits (1)
This repository contains a Proof-of-Concept (PoC) for CVE-2025-62221, a Use-After-Free (UAF) vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys). The exploit demonstrates a privilege escalation from user-mode to NT AUTHORITY\SYSTEM by manipulating memory objects through a race condition.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H