CVE-2025-62221: Microsoft Windows Use After Free Vulnerability
Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.
Other sources
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
— Microsoft
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7462Fixed in 10.0.26100.7392Patch KB5072014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8146Patch KB5071544 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6345Patch KB5071417 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4529Fixed in 10.0.20348.4467Patch KB5071413 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2025Patch KB5071542 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7462Fixed in 10.0.26200.7392Patch KB5072014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6691Patch KB5071546 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6691Patch KB5071546
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62221?
CVE-2025-62221 is classified with a high severity as it allows an authorized attacker to elevate privileges locally.
How do I fix CVE-2025-62221?
To fix CVE-2025-62221, apply the latest security updates and patches provided by Microsoft for affected Windows versions.
Which Microsoft products are affected by CVE-2025-62221?
CVE-2025-62221 affects several versions of Microsoft Windows including Windows 10, Windows 11, and Windows Server editions.
Can CVE-2025-62221 be exploited remotely?
No, CVE-2025-62221 requires local access for an attacker to exploit the vulnerability for privilege escalation.
What does 'use after free' mean in the context of CVE-2025-62221?
'Use after free' refers to a programming flaw where memory is accessed after it has been freed, potentially allowing attackers to execute arbitrary code.