CVE-2025-62221Disclosure(microsoft / windows_10_1809)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows_10_1809 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-12-30. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2
  • windows_11_23h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2019windows_server_2022windows_server_2022_23h2windows_server_2025

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-12: 1Mentions · 2026-07-15: 1PoC Mentioned / Linked · 2026-07-15: 1Active Exploitation · 2026-07-15: 1Patch / Workaround · 2026-07-15: 1Technical Details · 2026-02-12: 1Technical Details · 2026-07-15: 102-1207-15
Signal classification2 categories
Disclosure
150.0%
Exploit
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-121
Disclosure1
2026-07-151
Exploit1
Full discourse2 posts
  • chiefpie@cplearns2h4ck
    Exploit

    A bunch of my bugs are patched today. One fun bug is CVE-2026-58536, UAF in the cldflt.sys . It is a patch bypass of CVE-2025-62221, caught exploited ITW by Microsoft Threat Intel. I bypassed the patch and exploited it as part of the Microsoft Exploit Research Challenge. https://t.co/xzrQNcDnQh

    Post summary

    The author reports bypassing a patch for CVE-2026-58536, successfully exploiting the vulnerability as part of an exploit research challenge, indicating active exploitation and technical detail about the flaw.

    8181197538.9K
    2.4K followersView on X
  • Crowdfense@crowdfense
    Disclosure

    The following vulnerabilities have been added to our feed: - CVE-2025-64446: Fortinet Fortiweb Command Injection RCE - CVE-2025-62221: Microsoft Cloud Files Mini Filter Driver UAF LPE - CVE-2025-26666: Windows Media Heap-based Buffer Overflow DoS https://www.crowdfense.com/n-day-feed/

    Post summary

    The feed lists three newly added CVEs with brief technical descriptors, but provides no PoC, exploit code, active exploitation evidence, or patch details.

    00055808
    2.9K followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_11_25h2---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more