CVE-2025-49724
8.8Microsoft · Windows Connected Devices Platform Service
A use after free vulnerability exists in the Windows Connected Devices Platform Service, allowing an unauthenticated attacker to execute arbitrary code over a network.
Executive summary
A critical use after free vulnerability in the Windows Connected Devices Platform Service allows remote, unauthorized attackers to execute arbitrary code on affected Windows systems.
Vulnerability
This is a use after free flaw (CWE-416) within the Windows Connected Devices Platform Service. The vulnerability can be triggered by an unauthenticated attacker over the network, potentially resulting in remote code execution.
Business impact
Successful exploitation of this vulnerability poses a severe risk to organizational infrastructure, as it grants attackers the ability to execute arbitrary code with the privileges of the affected service. Given the CVSS score of 8.8, this vulnerability is classified as High severity, representing a significant threat to system confidentiality, integrity, and availability. Unauthorized code execution can lead to full system compromise, data exfiltration, or the deployment of ransomware.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide for CVE-2025-49724 to all vulnerable systems immediately.
Proactive Monitoring: Monitor network traffic for unusual activity originating from or directed toward the Connected Devices Platform Service, and review system event logs for signs of service crashes or unauthorized process execution.
Compensating Controls: Ensure that host-based firewalls are configured to restrict network access to the Connected Devices Platform Service to trusted internal segments only, reducing the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the severity of this vulnerability and the potential for remote code execution, organizations must prioritize patching affected Windows systems. IT administrators should verify that all endpoints are updated to the versions specified in the Microsoft security update guide to ensure comprehensive protection against this use after free flaw.