Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to deny service locally.
History

Thu, 11 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Description Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to deny service locally.
Title Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability
Weaknesses CWE-362
CWE-822
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published: 2025-09-09T17:01:25.368Z

Updated: 2025-09-12T00:49:15.564Z

Reserved: 2025-07-16T19:49:12.441Z

Link: CVE-2025-54114

cve-icon Vulnrichment

Updated: 2025-09-11T13:52:55.693Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-09T17:15:57.367

Modified: 2025-09-11T17:14:25.240

Link: CVE-2025-54114

cve-icon Redhat

No data.