Use-After-Free Local Privilege Escalation in Microsoft Windows Connected Devices Platform (Cdpsvc)
AI analysis
CVE-2026-69516 is a use-after-free (CWE-416) memory-corruption flaw in the Windows Connected Devices Platform Service (Cdpsvc), a service Microsoft ships and runs by default on modern Windows desktops. An authorized attacker who already has a low-privileged foothold on the machine can trigger the flaw by racing the service's memory handling, causing it to reuse freed memory; the high attack-complexity rating indicates timing is not trivially reliable. Successful exploitation elevates the attacker's privileges locally, yielding high impact on confidentiality, integrity, and availability of the host, and is a typical link in chains that pair a local escalation with remote code execution. Any Windows system running Cdpsvc is affected; the flaw was patched in Microsoft's September 2026 Patch Tuesday release, which addressed 966 flaws including 2 zero-days. There is no known public proof-of-concept, no CISA KEV listing, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days.
What to do: Apply Microsoft's September 2026 Patch Tuesday updates to all Windows 10 and Windows 11 endpoints; no workarounds for this service are documented, so patching is the primary mitigation. Given the absence of a public PoC, KEV listing, and low EPSS, standard patch-cycle prioritization is acceptable, but bundle it with the other local privilege-escalation fixes from the same release to disrupt common RCE-to-SYSTEM attack chains.
Affected
| Microsoft Windows Connected Devices Platform Service (Cdpsvc) | — |
Estimated exposure
masson the order of 1 billion Windows devices (Cdpsvc runs by default on Windows 10/11) — Cdpsvc is enabled by default on Windows 10 and Windows 11, whose combined installed base is on the order of a billion devices, so exposure breadth is effectively the Windows desktop fleet; exploitation requires local access and…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.