CVE-2025-62221

HIGH KEV

Windows Cloud Files Mini Filter Driver - Use-After-Free

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-62221 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added December 9, 2025. EIP tracks 1 public exploit from researchers including Teodor1231241.

AI-analyzed exploit summary This repository contains a Proof-of-Concept (PoC) for CVE-2025-62221, a Use-After-Free (UAF) vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys). The exploit demonstrates a privilege escalation from user-mode to NT AUTHORITY\SYSTEM by manipulating memory objects through a race condition.

Description

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Exploits (1)

nomisec WORKING POC
by Teodor1231241 · poc
https://github.com/Teodor1231241/DEMO-Proof-of-Concept-Temporal-Memory-Inconsistency-in-cldflt.sys-CVE-2025-62221

This repository contains a Proof-of-Concept (PoC) for CVE-2025-62221, a Use-After-Free (UAF) vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys). The exploit demonstrates a privilege escalation from user-mode to NT AUTHORITY\SYSTEM by manipulating memory objects through a race condition.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: Windows Cloud Files Mini Filter Driver (cldflt.sys)
No auth needed
Prerequisites: Windows system with cldflt.sys loaded · Local user access · Mininet-simulated network topology for testing
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0152
EPSS Percentile 81.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2025-12-09
VulnCheck KEV 2025-12-09
ENISA EUVD EUVD-2025-202200
CWE
CWE-416
Status published
Products (23)
Microsoft/Windows 10 Version 1809 10.0.17763.0 - 10.0.17763.8146
Microsoft/Windows 10 Version 21H2 10.0.19044.0 - 10.0.19044.6691
Microsoft/Windows 10 Version 22H2 10.0.19045.0 - 10.0.19045.6691
Microsoft/Windows 11 version 22H3 10.0.22631.0 - 10.0.22631.6345
Microsoft/Windows 11 Version 23H2 10.0.22631.0 - 10.0.22631.6345
Microsoft/Windows 11 Version 24H2 10.0.26100.0 - 10.0.26100.7462
Microsoft/Windows 11 Version 25H2 10.0.26200.0 - 10.0.26200.7462
Microsoft/Windows Server 2019 10.0.17763.0 - 10.0.17763.8146
Microsoft/Windows Server 2019 (Server Core installation) 10.0.17763.0 - 10.0.17763.8146
Microsoft/Windows Server 2022 10.0.20348.0 - 10.0.20348.4529
... and 13 more
Published Dec 09, 2025
KEV Added Dec 09, 2025
Tracked Since Feb 18, 2026