Microsoft Windows Connected Devices Platform Service Privilege Escalation Vulnerability

Vulnerability

A use-after-free vulnerability has been identified in the Windows Connected Devices Platform Service, allowing an authorized attacker to locally elevate privileges. This vulnerability affects several versions of Windows, including Windows Server 2016, Windows 10 Version 1607, Windows Server 2025, Windows 11 Version 24H2, Windows Server 2022, and Windows 11 Version 23H2.

Impact

Exploitation of this vulnerability could allow an attacker to elevate privileges from Medium Integrity Level to Local Service.

Remediation

Users can apply the security update KB5062560 for Windows Server 2016 and Windows 10 Version 1607. For Windows Server 2025, the security update is KB5062553. Windows 11 users can apply KB5062553 for both x64-based and ARM64-based systems. Windows Server 2022 users can apply KB5062570, while those on Windows 11 Version 23H2 for x64-based and ARM64-based Systems can use KB5062552.

Added: Jul 8, 2025, 10:01 PM
Updated: Jul 8, 2025, 10:01 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.9
exploitability
3.3
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.