ZeroHour

CVE-2026-83991

PoC mass

Missing Authentication in Windows Cloud Files Mini Filter Enables Local Tampering

CVSS 3.1
5.5 medium
EPSS
<1%p27
Published
()
Modified
AI analysis

CVE-2026-83991 is a missing-authentication flaw (CWE-306) in the Windows Cloud Files Mini Filter Driver, the kernel component that handles cloud placeholder files such as OneDrive Files On-Demand. A local attacker who already has low-privileged authorized access to a machine can invoke the driver's critical function without proper authentication checks and tamper with cloud-managed file data, with high integrity impact but no confidentiality or availability loss per the CVSS vector. Because the attack vector is local (AV:L) with required privileges of only a standard user, it does not by itself enable remote compromise; it matters most on shared or multi-user systems where untrusted users hold local accounts. All supported Windows 10 releases from 1809 onward, Windows 11 from 23H2 onward, and Windows Server 2019/2022/2025 are listed as affected. The flaw is not in CISA's KEV, its EPSS score is a low 0.3%, but a public proof-of-concept write-up exists on GitHub, and Microsoft shipped a fix as part of its September 2026 Patch Tuesday release.

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates to all affected Windows 10, Windows 11, and Windows Server builds. Prioritize shared workstations, VDI hosts, and servers where low-privileged or untrusted users have local sign-in rights, since exploitation requires local access and only tampers with cloud files data. No in-the-wild exploitation is reported (EPSS 0.3%, not in KEV), but a public PoC exists, so treat the patch as routine-high priority rather than emergency.

Affected
microsoft Windows 10 1809Windows 10 version 1809 (all builds prior to the September 2026 security update)
microsoft Windows 10 21H2Windows 10 version 21H2 (all builds prior to the September 2026 security update)
microsoft Windows 10 22H2Windows 10 version 22H2 (all builds prior to the September 2026 security update)
microsoft Windows 11 23H2Windows 11 version 23H2 (all builds prior to the September 2026 security update)
microsoft Windows 11 24H2Windows 11 version 24H2 (all builds prior to the September 2026 security update)
microsoft Windows 11 25H2Windows 11 version 25H2 (all builds prior to the September 2026 security update)
microsoft Windows 11 26H1Windows 11 version 26H1 (all builds prior to the September 2026 security update)
microsoft Windows Server 2019Windows Server 2019 (all builds prior to the September 2026 security update)
microsoft Windows Server 2022Windows Server 2022 (all builds prior to the September 2026 security update)
microsoft Windows Server 2025Windows Server 2025 (all builds prior to the September 2026 security update)
Estimated exposure
masshundreds of millions of Windows devices (Windows 10/11 installed base exceeds 1 billion machines) — The Cloud Files Mini Filter Driver ships with the listed Windows 10, Windows 11, and Windows Server releases, whose combined installed base is over a billion devices, though actual exploitability requires a local low-privileged account…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.

Vendors
microsoft
Products
windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-306
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

Microsoft Patch Tuesday Update September 2026 – 974 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities across Windows and Office, including two actively exploited Windows privilege-escalation zero-days.

Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities spanning Windows, Office, SQL Server, SharePoint, Exchange, Azure, and developer tools. Two Windows zero-days are confirmed exploited in attacks: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a Windows Update Stack privilege-escalation flaw involving link following. The release also includes Critical fixes for Windows Secure Kernel Mode, VBS Enclave, Excel, and Word.

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs