CVE-2026-20864

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

high 7.8 CVSS 3.1
Published: Jan 13, 2026
Modified: May 26, 2026
Vendor: Microsoft
Product: Windows 10 1809

Description

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

References

Related CVEs