Elevation of Privilege in Windows Cloud Files Mini Filter Driver by Microsoft
CVE-2026-58536

7.8HIGH

What is CVE-2026-58536?

CVE-2026-58536 is a vulnerability affecting the Windows Cloud Files Mini Filter Driver developed by Microsoft. This component is essential for managing cloud storage interactions within the Windows operating system, facilitating the handling of cloud-based files seamlessly alongside local files. The vulnerability pertains to a "use after free" flaw, allowing an authorized attacker to elevate their privileges on the system. If exploited, this could enable the attacker to gain unauthorized access to sensitive system components or data, compromising the integrity and security of the entire system. The potential for abuse is significant, particularly for systems that handle critical business processes or sensitive information.

Potential impact of CVE-2026-58536

  1. Unauthorized Access: The vulnerability allows attackers with valid credentials to execute local privilege escalation, potentially leading to unauthorized access to restricted system areas and data. This could result in data theft or manipulation.

  2. System Compromise: By leveraging this privilege elevation, an attacker can compromise system controls, leading to full administrative access. This may enable further exploitation, risking additional exposure of the organization’s digital assets.

  3. Increased Attack Surface: The existence of this vulnerability expands the possible attack vectors for malicious actors. If exploited, it may provide a foothold for broader attacks, possibly connecting to other vulnerabilities or weaknesses within the infrastructure.

Affected Version(s)

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9020

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7548

Windows 10 Version 22H2 32-bit Systems 10.0.19045.0 < 10.0.19045.7548

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.