Impact
Heap‑based buffer overflow in the Connected Devices Platform Service (Cdpsvc) allows an authorized local attacker to gain elevated privileges. The overflow occurs because the service does not properly bound the heap buffer during writes, enabling the attacker to corrupt service state and increase their privilege level. The flaw is a CWE‑122 type vulnerability that permits privilege escalation for users with sufficient local authorization.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 22H3, 23H2, 24H2, and 25H2; Microsoft Windows Server 2019 (standard and Server Core), Windows Server 2022 (standard and Server Core 23H2 edition), and Windows Server 2025 (standard and Server Core).
Risk and Exploitability
The CVSS base score of 7.8 classifies this issue as high severity, indicating that while it affects a privileged service, it requires local authorization to exploit. The EPSS score is reported as less than 1%, showing a low probability of exploitation in the field. No exploits are publicly known and it is not listed in the CISA KEV catalog. An attacker would need to execute malicious code while logged in as a user with sufficient rights to trigger the heap buffer overflow.
OpenCVE Enrichment