Microsoft disclosed CVE-2025-62221 and CVE-2025-62454, two elevation-of-privilege vulnerabilities in the Windows Cloud Files Mini Filter Driver, and released security updates to address them. The company identified CVE-2025-62221 as an Important flaw caused by a use-after-free condition (CWE-416) that could allow a local attacker with low privileges to gain SYSTEM privileges without user interaction.
Microsoft assigned CVE-2025-62221 a CVSS v3.1 score of 7.8 and said exploitation had been detected in the wild at the time of disclosure, although the vulnerability had not been publicly disclosed beforehand. Advisory listings for CVE-2025-62454 also classify it as a Windows Cloud Files Mini Filter Driver elevation-of-privilege issue, indicating multiple privilege-escalation weaknesses in the same Windows component were addressed in the release.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft also published Security Update Guide entries for CVE-2025-62454, another Windows Cloud Files Mini Filter Driver elevation-of-privilege vulnerability. The provided references do not include technical details beyond the advisory publication itself.
Microsoft published an advisory for CVE-2025-62221, an Important Windows Cloud Files Mini Filter Driver elevation-of-privilege vulnerability caused by a use-after-free flaw. The company said the bug could be exploited locally by a low-privileged attacker to gain SYSTEM privileges, noted exploitation in the wild, and made a fix available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.