ZeroHour

CVE-2026-69516

mass

Use-After-Free Local Privilege Escalation in Microsoft Windows Connected Devices Platform (Cdpsvc)

CVSS 3.1
7.0 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-69516 is a use-after-free (CWE-416) memory-corruption flaw in the Windows Connected Devices Platform Service (Cdpsvc), a service Microsoft ships and runs by default on modern Windows desktops. An authorized attacker who already has a low-privileged foothold on the machine can trigger the flaw by racing the service's memory handling, causing it to reuse freed memory; the high attack-complexity rating indicates timing is not trivially reliable. Successful exploitation elevates the attacker's privileges locally, yielding high impact on confidentiality, integrity, and availability of the host, and is a typical link in chains that pair a local escalation with remote code execution. Any Windows system running Cdpsvc is affected; the flaw was patched in Microsoft's September 2026 Patch Tuesday release, which addressed 966 flaws including 2 zero-days. There is no known public proof-of-concept, no CISA KEV listing, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's September 2026 Patch Tuesday updates to all Windows 10 and Windows 11 endpoints; no workarounds for this service are documented, so patching is the primary mitigation. Given the absence of a public PoC, KEV listing, and low EPSS, standard patch-cycle prioritization is acceptable, but bundle it with the other local privilege-escalation fixes from the same release to disrupt common RCE-to-SYSTEM attack chains.

Affected
Microsoft Windows Connected Devices Platform Service (Cdpsvc)
Estimated exposure
masson the order of 1 billion Windows devices (Cdpsvc runs by default on Windows 10/11) — Cdpsvc is enabled by default on Windows 10 and Windows 11, whose combined installed base is on the order of a billion devices, so exposure breadth is effectively the Windows desktop fleet; exploitation requires local access and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1