CVE-2026-69279
massUse-After-Free LPE in Windows Cloud Files Mini Filter Driver
CVE-2026-69279 is a use-after-free memory corruption flaw (CWE-416) in the Windows Cloud Files Mini Filter Driver (cldflt.sys), the kernel filter driver that supports cloud-sync placeholders such as OneDrive Files On-Demand. It is triggered locally by an authorized attacker who already has low-privileged code execution on the machine; the high attack-complexity score suggests exploitation depends on a specific timing or state condition when the driver handles freed memory. A successful exploit yields local privilege elevation with high impact on confidentiality, integrity, and availability, effectively letting a standard user gain higher privileges on the host. Any Windows system on which the Cloud Files Mini Filter Driver is loaded is in scope, and the vendor (Microsoft, the assigned CNA) has not specified affected version ranges in the available data. As of this analysis there is no known exploitation: it is absent from CISA KEV, no public proof-of-concept exists, and EPSS puts 30-day exploitation probability at just 0.3% (17th percentile).
What to do: Apply Microsoft's fix through Windows Update as soon as it is released; no workaround is documented in the available data. Because this requires an authorized local account with high attack complexity, prioritize patching shared workstations, multi-user servers, and hosts where standard users can run code. You can gauge relevance on a host by checking whether the cldflt.sys filter is loaded (e.g., 'fltmc instances'), which typically occurs when OneDrive Files On-Demand or similar cloud sync features are in use.
| Microsoft Windows Cloud Files Mini Filter Driver (cldflt.sys) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.