CVE-2025-21207

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 400

Summary

CVE-2025-21207 is a newly disclosed Denial of Service (DoS) vulnerability affecting the Windows Connected Devices Platform Service (Cdpsvc). An attacker can exploit this flaw by sending maliciously crafted data packets to a targeted system, causing the Cdpsvc service to crash and become unresponsive. This may result in significant network disruptions and potential downtime for affected organizations. Microsoft has released a security update to address this issue, and it's highly recommended that users install this patch as soon as possible to mitigate the risks associated with CVE-2025-21207.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share