ZeroHour

CVE-2026-69478

mass

Heap Overflow in Windows Device Association Service Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-69478 is a heap-based buffer overflow (CWE-122) in the Windows Device Association Service, the built-in Windows component (DasHost.exe) that manages pairing and association between the system and connected devices. The flaw is triggered by an authorized attacker - a user or process with an existing local account and low privileges - who supplies input that overflows a heap buffer used by the service; no user interaction or remote access is required. Successful exploitation yields code execution in the service's privileged context, giving the attacker elevated (SYSTEM-level) privileges on the local machine with high impact to confidentiality, integrity, and availability. Any Windows installation running an affected version of the Device Association Service is exposed, though the provided data does not specify which Windows versions or builds are affected, so defenders should confirm exact scope against Microsoft's advisory. Exploitation has not been observed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at just 0.3%.

What to do: Apply the Microsoft monthly cumulative Windows update that addresses CVE-2026-69478 as soon as it is available, prioritizing shared systems where local standard users are less trusted (VDI, kiosks, RDS/terminal hosts, developer workstations). Because the provided data does not list affected builds, verify scope against Microsoft's advisory rather than assuming all Windows versions are affected. No in-the-wild exploitation is currently known, so a standard patch-cycle timeline is defensible, but do not defer beyond the next patch cycle given the high-severity SYSTEM-level impact.

Affected
Microsoft Windows (Device Association Service)
Estimated exposure
mass≈hundreds of millions of Windows endpoints (service ships by default in Windows) — The Device Association Service is a default Windows component present across client and server SKUs, and the active Windows install base is publicly estimated on the order of a billion devices, so exposure is plausibly hundreds of millions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.