LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-62221: Microsoft Windows Use After Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 9, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 30, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-62221 to its Known Exploited Vulnerabilities catalog on Dec 9, 2025, with a federal patch deadline of Dec 30, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.

A use-after-free vulnerability in the Microsoft Windows Cloud Files Mini Filter Driver allows an authorized local attacker to elevate privileges on affected systems. This matters because successful exploitation can grant higher access rights without remote entry, increasing the risk of further compromise on Windows environments where the driver is active.

How it works

The weakness is categorized as CWE-416, a use-after-free condition. In this class of flaw, memory is released but a reference to it remains in use. An attacker with local authorization can trigger the Cloud Files Mini Filter Driver to dereference the freed memory, resulting in local privilege escalation. Exact trigger conditions and code paths must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that load the Cloud Files Mini Filter Driver. Inventory Windows endpoints and servers through standard asset management tools or driver enumeration commands to identify presence of the driver. Check configurations and versions against the vendor advisory, as not all installations may expose the affected code path. No specific log signatures or telemetry indicators are documented in the available facts; monitor for anomalous local process behavior consistent with privilege changes.

How to remediate

Apply mitigations per the vendor instructions as the primary step. For this class of kernel driver vulnerability, confirm the availability of an updated driver or operating system component through official Microsoft channels. Follow applicable BOD 22-01 guidance where cloud services are involved. After updating, review driver loading policies and restrict unnecessary use of Cloud Files features to limit exposure.

If you can't patch immediately

Apply mitigations per vendor instructions while planning the update. Where mitigations cannot be implemented, discontinue use of the affected product. Segment systems that rely on the Cloud Files Mini Filter Driver to reduce the blast radius of any local escalation. Monitor authentication and process creation events for unexpected privilege changes until remediation is complete.

If your data may have been exposed

Actively exploited vulnerabilities lead to breaches. You can run a free exposure scan of your email to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-416
Added to CISA KEVDec 9, 2025
Federal patch deadlineDec 30, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities