Executive brief
A security vulnerability exists in a Windows component responsible for managing cloud-based files, such as those used by OneDrive. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new accounts with full user rights.
Technical details
A use-after-free (UAF) vulnerability exists in the Windows Cloud Files Mini Filter Driver (cldflt.sys). The flaw is triggered when the driver improperly handles objects in memory, allowing an attacker to reference memory after it has been freed. To exploit this, an attacker must first have local access to the target system with low-privileged user credentials. Successful exploitation enables the attacker to execute arbitrary code with SYSTEM privileges, effectively bypassing local security boundaries. Microsoft has released security updates to address this issue by correcting how the driver manages memory object lifecycles.
Affected products
- Microsoft Windows
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory