H-ISAC TLP White Vulnerability Bulletin: Microsoft Windows Cloud Files Minifilter Privilege Escalation Vulnerability

In March 2024, Exodus Intelligence discovered a vulnerability in Microsoft Windows Cloud Files Minifilter driver. The patch for this flaw was recently released, included in Microsoft's October 2025 Patch Tuesday, and is tracked as CVE-2025-55680.

The flaw is considered critical with a CVSS score of 7.8, which is a race condition vulnerability in the said driver, allowing threat actors to elevate privileges and create arbitrary files on systems when exploited.

Health-ISAC is sharing this to increase situational awareness and encourage organizations to assess their level of risk to this vulnerability.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272