Impact
The vulnerability is a use‑after‑free in the Connected Devices Platform Service (Cdpsvc), allowing a local authenticated attacker to gain higher privileges by accessing memory after it has been freed. This flaw maps to CWE‑416 and can lead to arbitrary execution or modification of protected data when successfully exploited.
Affected Systems
Affected systems include Microsoft Windows 10 build 1809, 21H2, and 22H2, Windows 11 builds 23H2, 24H2, 25H2, and 26H1, and Windows Server 2019, 2022, and 2025, both standard and Server Core installations. The service is present on all listed releases and is the component targeted by the vulnerability.
Risk and Exploitability
The CVSS score of 7 indicates a high impact for local privilege escalation. EPSS data is not available, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector requires an authenticated local user with the ability to interact with Cdpsvc; an attacker would trigger the use‑after‑free condition through crafted inputs or actions that manipulate the service’s memory, then leverage the escalated privileges to compromise system integrity or execute higher‑privileged code.
OpenCVE Enrichment