PT-2025-50155 · Microsoft · Windows
Published
2025-12-09
·
Updated
2026-01-24
·
CVE-2025-62221
CVSS v3.1
7.8
7.8
High
| Base vector | Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to December 2025 Patch Tuesday
Description
A use-after-free condition exists in the Windows Cloud Files Mini Filter Driver. Successful exploitation of this issue allows an authorized attacker to gain elevated privileges locally, potentially reaching SYSTEM-level access. This vulnerability, identified as CVE-2025-62221, is actively exploited in the wild and has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of December 30, 2025. The vulnerability is present in the
cldflt.sys driver, a component used by cloud file synchronization services like OneDrive and Google Drive. An attacker with local code execution rights can manipulate cloud file sync operations to exploit the vulnerability and escalate their privileges. The issue impacts Windows 10 and later versions.Recommendations
Apply the December 2025 Patch Tuesday update to all affected systems immediately.
Fix
RCE
LPE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-15480
CVE-2025-62221
Affected Products
Windows
References · 61
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-62221 · Vendor Advisory
- https://safe-surf.ru/specialists/bulletins-nkcki/727082 · Security Note
- https://bdu.fstec.ru/vul/2025-15480 · Security Note
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62221 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-62221 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-62221 · Security Note
- https://msrc.microsoft.com/update-guide/en-us/advisory/CVE-2025-62221 · Vendor Advisory
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-62221 · Vendor Advisory
- https://reddit.com/r/pwnhub/comments/1pjan2l/microsoft_issues_security_fixes_for_56_flaws · Reddit Post
- https://reddit.com/r/SecOpsDaily/comments/1pk8w7y/cve202562221_and_cve202554100_windows_elevation · Reddit Post
- https://twitter.com/johndjohnson/status/1999149040144183601 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1potrly/top_10_trending_cves_17122025 · Reddit Post
- https://t.me/true_secator/7711 · Telegram Post
- https://t.me/avleonovcom/1612 · Telegram Post
- https://twitter.com/ScyScan/status/2003011540749046022 · Twitter Post