Executive brief
A security vulnerability has been identified in a Windows background service responsible for connecting devices like phones and tablets to computers. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could allow them to bypass security restrictions, access sensitive data, or install malicious software across the affected workstation or server.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists within the Windows Connected Devices Platform Service (Cdpsvc). The flaw is triggered when the service improperly handles memory allocation on the heap, allowing an attacker to overwrite adjacent memory space. To exploit this, an attacker must first have local access to the system with low-privileged user credentials. Successful exploitation allows the attacker to execute arbitrary code with elevated system privileges. Microsoft has released security updates to address this issue across supported versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 23H2, 24H2, 25H2
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
- Microsoft Windows Server 2025 All versions
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory: Microsoft released the initial advisory and security updates.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20864
- https://www.vicarius.io/vsociety/posts/cve-2026-20864-detection-script-heap-based-buffer-overflow-in-windows-connected-devices-platform-service
- https://www.vicarius.io/vsociety/posts/cve-2026-20864-mitigation-script-heap-based-buffer-overflow-in-windows-connected-devices-platform-service