Skip to content

CVE-2025-62221

CVE

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
December 9, 2025
Last Seen
December 11, 2025
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Microsoft Office 2016 to 2024 and Office 365 apps are affected by a zero-day vulnerability (CVE-2026-21509) that is currently being exploited in attacks. Microsoft has released emergency security updates to address this issue.

A use after free vulnerability in the Windows Cloud Files Mini Filter Driver allows authorized attackers to elevate privileges locally. This vulnerability is documented as CVE-2025-62221 and is referenced in CISA's BOD 22-01 and the Known Exploited Vulnerabilities Catalog for further guidance. Users...

A significant vulnerability, tracked as CVE-2025-62221, was disclosed on December 9, 2025, affecting Windows environments. This flaw poses a risk to users relying on the Windows Cloud Files Mini Filter Driver, potentially allowing unauthorized access to sensitive data.

In December 2025, Adobe released five bulletins addressing 139 unique vulnerabilities as part of its security updates. This follows the November updates, where Adobe addressed 29 unique CVEs across several products. Microsoft also provided updates during this final patch Tuesday of the year.

Public Exploits

Checking GitHub for proof-of-concept code…