ZeroHour

CVE-2026-69314

mass

Use-After-Free Privilege Escalation in Windows Device Association Broker

CVSS 3.1
7.1 high
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-69314 is a use-after-free memory corruption flaw (CWE-416) in the Windows Device Association Broker service. An attacker who already holds low-privileged credentials must send network input under conditions of high complexity and obtain user interaction, triggering the freed-memory condition in the service. Successful exploitation lets the attacker elevate privileges on the targeted Windows host with high impact on confidentiality, integrity, and availability. All Windows systems running the Device Association Broker service are potentially affected; Microsoft has not published fixed version details in this data. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known, and EPSS estimates only a 0.5% chance of exploitation in the next 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69314 as soon as it is released via Windows Update or WSUS, prioritizing hosts where untrusted or low-privileged users have network logon access. Until patched, restrict standard-user remote access to sensitive Windows hosts and monitor for anomalous privilege escalation events. Since no exploit is publicly known, this is a routine patch-cycle item rather than an emergency, but verify the update applies to your Windows editions once version specifics are published.

Affected
Microsoft Windows (Device Association Broker service)
Estimated exposure
masshundreds of millions of Windows devices (Windows runs on roughly a billion-plus devices and the broker service ships by default in modern Windows client… — Windows has an install base exceeding one billion devices and the Device Association Broker is a default OS component, though practical exploitability is limited to authenticated attackers with user interaction.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.