Record summary

CVE-2025-59191 has a selected CVSS score of 7.8 (high).

Description

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2025 · Source: CVE List

Affected products and versions

Showing 12 of 14
ProductSourceVersion rangeStatus
CVE List10.0.17763.0 to < 10.0.17763.7919affected
CVE List10.0.19044.0 to < 10.0.19044.6456affected
CVE List10.0.19045.0 to < 10.0.19045.6456affected
CVE List10.0.22631.0 to < 10.0.22631.6060affected
CVE List10.0.26100.0 to < 10.0.26100.6899affected
CVE List10.0.26200.0 to < 10.0.26200.6899affected
CVE List10.0.22621.0 to < 10.0.22621.6060affected
CVE List10.0.22631.0 to < 10.0.22631.6060affected
CVE List10.0.17763.0 to < 10.0.17763.7919affected

Windows Server 2019 (Server Core installation)

Browse Microsoft / Windows Server 2019 (Server Core installation)
CVE List10.0.17763.0 to < 10.0.17763.7919affected
CVE List10.0.20348.0 to < 10.0.20348.4294affected

Windows Server 2022, 23H2 Edition (Server Core installation)

Browse Microsoft / Windows Server 2022, 23H2 Edition (Server Core installation)
CVE List10.0.25398.0 to < 10.0.25398.1913affected

References

2