Missing Authentication in Windows Cloud Files Mini Filter Enables Local Tampering
AI analysis
CVE-2026-83991 is a missing-authentication flaw (CWE-306) in the Windows Cloud Files Mini Filter Driver, the kernel component that handles cloud placeholder files such as OneDrive Files On-Demand. A local attacker who already has low-privileged authorized access to a machine can invoke the driver's critical function without proper authentication checks and tamper with cloud-managed file data, with high integrity impact but no confidentiality or availability loss per the CVSS vector. Because the attack vector is local (AV:L) with required privileges of only a standard user, it does not by itself enable remote compromise; it matters most on shared or multi-user systems where untrusted users hold local accounts. All supported Windows 10 releases from 1809 onward, Windows 11 from 23H2 onward, and Windows Server 2019/2022/2025 are listed as affected. The flaw is not in CISA's KEV, its EPSS score is a low 0.3%, but a public proof-of-concept write-up exists on GitHub, and Microsoft shipped a fix as part of its September 2026 Patch Tuesday release.
What to do: Apply Microsoft's September 2026 Patch Tuesday security updates to all affected Windows 10, Windows 11, and Windows Server builds. Prioritize shared workstations, VDI hosts, and servers where low-privileged or untrusted users have local sign-in rights, since exploitation requires local access and only tampers with cloud files data. No in-the-wild exploitation is reported (EPSS 0.3%, not in KEV), but a public PoC exists, so treat the patch as routine-high priority rather than emergency.
Affected
| microsoft Windows 10 1809 | Windows 10 version 1809 (all builds prior to the September 2026 security update) |
| microsoft Windows 10 21H2 | Windows 10 version 21H2 (all builds prior to the September 2026 security update) |
| microsoft Windows 10 22H2 | Windows 10 version 22H2 (all builds prior to the September 2026 security update) |
| microsoft Windows 11 23H2 | Windows 11 version 23H2 (all builds prior to the September 2026 security update) |
| microsoft Windows 11 24H2 | Windows 11 version 24H2 (all builds prior to the September 2026 security update) |
| microsoft Windows 11 25H2 | Windows 11 version 25H2 (all builds prior to the September 2026 security update) |
| microsoft Windows 11 26H1 | Windows 11 version 26H1 (all builds prior to the September 2026 security update) |
| microsoft Windows Server 2019 | Windows Server 2019 (all builds prior to the September 2026 security update) |
| microsoft Windows Server 2022 | Windows Server 2022 (all builds prior to the September 2026 security update) |
| microsoft Windows Server 2025 | Windows Server 2025 (all builds prior to the September 2026 security update) |
Estimated exposure
masshundreds of millions of Windows devices (Windows 10/11 installed base exceeds 1 billion machines) — The Cloud Files Mini Filter Driver ships with the listed Windows 10, Windows 11, and Windows Server releases, whose combined installed base is over a billion devices, though actual exploitability requires a local low-privileged account…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.