CVE detail
CVE-2025-62221
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- U.S. CISA adds Microsoft Windows and WinRAR flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows and WinRAR flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft Windows and WinRAR flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: CVE-2025-6218 is a WinRAR directory traversal flaw (formerly […]
newssecurityaffairs.comDec 10, 2025, 9:33 AM - Microsoft Patch Tuesday security updates for December 2025 fixed an actively exploited zero-daySecurity Affairs
Microsoft Patch Tuesday security updates for December 2025 address 57 vulnerabilities, including three critical flaws. Microsoft Patch Tuesday security updates for December 2025 addressed 57 vulnerabilities in Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Exchange Server, Azure, Copilot, PowerShell, and Windows Defender. Three vulnerabilities are rated Critical, while the rest are […]
newssecurityaffairs.comDec 10, 2025, 8:47 AM - December Patch Tuesday: Windows Cloud Files Mini Filter Driver hole already being exploitedCSO Online
Microsoft is finishing 2025 by issuing only 57 patches for Windows and other products for December Patch Tuesday, but one vulnerability is already being exploited as a zero day and needs to be addressed fast. It’s an escalation of privilege vulnerability in Windows Cloud Files Mini Filter Driver (CVE-2025-62221), described as a use-after-free problem in […]
newswww.csoonline.comDec 10, 2025, 1:19 AM Microsoft has addressed a Windows vulnerability exploited as zero-day that allows attackers to obtain System privileges.
newswww.securityweek.comDec 9, 2025, 8:29 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-42825CVSS 7.0 · High
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-40415CVSS 8.1 · High
Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- CVE-2026-40410CVSS 7.0 · High
Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
- CVE-2026-40408CVSS 7.8 · High
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
- CVE-2026-40406CVSS 7.5 · High
Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-40382CVSS 7.8 · High
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.