CVE-2026-35418: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Other sources
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8755Patch KB5087538 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2113Patch KB5089548 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32860Fixed in 10.0.26100.32772Patch KB5087423 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7219Patch KB5093998 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7079Patch KB5087420 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8457Fixed in 10.0.26100.8390Patch KB5089466 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8457Fixed in 10.0.26200.8390Patch KB5089466 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7417Patch KB5094127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2330Patch KB5087541 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7291Patch KB5087544 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5139Fixed in 10.0.20348.5074Patch KB5087424
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35418?
CVE-2026-35418 has been assigned a high severity rating due to its potential to allow unauthorized local privilege escalation.
How can I fix CVE-2026-35418?
To remediate CVE-2026-35418, you should apply the official security updates provided by Microsoft for affected Windows versions.
Which systems are affected by CVE-2026-35418?
CVE-2026-35418 affects several systems including Windows 10 versions 1809 and 21H2, Windows 11, and various iterations of Windows Server.
What impact does CVE-2026-35418 have on systems?
CVE-2026-35418 allows authorized attackers to elevate their privileges, potentially leading to unauthorized access to sensitive data or system control.
Is CVE-2026-35418 exploitable remotely?
No, CVE-2026-35418 is primarily a local privilege escalation vulnerability and cannot be exploited remotely.