CVE-2025-62457
BaseFortify
Publication date: 2025-12-09
Last updated on: 2025-12-12
Assigner: Microsoft Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | windows_10_1809 | to 10.0.17763.8146 (inc) |
| microsoft | windows_10_21h2 | to 10.0.19044.6691 (inc) |
| microsoft | windows_10_22h2 | to 10.0.19045.6691 (inc) |
| microsoft | windows_11_23h2 | to 10.0.22631.6345 (inc) |
| microsoft | windows_server_2019 | to 10.0.17763.8146 (inc) |
| microsoft | windows_server_2022_23h2 | to 10.0.25398.2025 (inc) |
| microsoft | windows_11_24h2 | to 10.0.26100.7392 (inc) |
| microsoft | windows_11_25h2 | to 10.0.26200.7392 (inc) |
| microsoft | windows_server_2025 | to 10.0.26100.7392 (inc) |
| microsoft | windows | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
What immediate steps should I take to mitigate this vulnerability?
Apply the security updates provided by Microsoft for the Windows Cloud Files Mini Filter Driver as soon as they are available to mitigate the elevation of privilege vulnerability. [1]
Can you explain this vulnerability to me?
This vulnerability is an out-of-bounds read in the Windows Cloud Files Mini Filter Driver. It allows an authorized attacker to read memory outside the intended bounds, which can lead to privilege escalation locally on the affected system.
How can this vulnerability impact me? :
The vulnerability can allow an authorized attacker to elevate their privileges on the affected Windows system, potentially gaining higher-level access and control than intended, which can compromise system security and data integrity.