Junglewise Threat Intelligence

CVE-2026-69516: Microsoft Windows Connected Devices Platform Service use-after-free privilege escalation

CVE-2026-69516 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

The Connected Devices Platform Service (Cdpsvc) in Windows contains a use-after-free vulnerability that allows an authorized local attacker to execute arbitrary code with elevated privileges. This could enable a malicious user or compromised application to gain administrative access to the system and take full control of the device.

Technical details

The vulnerability is a use-after-free flaw in the Connected Devices Platform Service (Cdpsvc), a Windows system service that manages device-to-device connectivity features. An authorized attacker with local access to the system can trigger the use-after-free condition to achieve privilege escalation. The attack requires prior authentication or an existing user account on the target system. Exploitation allows the attacker to execute arbitrary code in the context of the service, typically running with SYSTEM privileges. A patch has been released by Microsoft to address this vulnerability.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats