Junglewise Threat Intelligence

CVE-2026-34337: Microsoft Windows use after free in Cloud Files Mini Filter Driver

CVE-2026-34337 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in a Windows component responsible for managing cloud-based files, such as those used by OneDrive. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A use-after-free (UAF) vulnerability exists in the Windows Cloud Files Mini Filter Driver (cldflt.sys). The flaw is rooted in improper synchronization during concurrent execution, leading to a race condition where the driver attempts to access memory that has already been freed. To exploit this, an attacker must have local access to the target system with low-privileged user credentials. Successful exploitation allows the attacker to execute code with SYSTEM privileges, effectively bypassing local security boundaries. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Microsoft published the security update guide.

References

Related threats