CVE-2025-55326 is a high-severity use-after-free vulnerability in the Connected Devices Platform Service (Cdpsvc) affecting multiple versions of Microsoft Windows 10, 11, and Server. This flaw allows an unauthenticated attacker to achieve remote code execution over a network, though successful exploitation requires high attack complexity and user interaction. While not currently listed in CISA's KEV catalog and lacking public exploit code, its high CVSS score of 7.5 and notable media coverage indicate significant potential impact. The vulnerability has garnered some community discussion and media attention, suggesting it is on the radar of security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.7919CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* | ||
< 10.0.19044.6456CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.6456CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22621.6060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22631.6060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.