CVE-2026-69478
massHeap Overflow in Windows Device Association Service Allows Local Privilege Escalation
CVE-2026-69478 is a heap-based buffer overflow (CWE-122) in the Windows Device Association Service, the built-in Windows component (DasHost.exe) that manages pairing and association between the system and connected devices. The flaw is triggered by an authorized attacker - a user or process with an existing local account and low privileges - who supplies input that overflows a heap buffer used by the service; no user interaction or remote access is required. Successful exploitation yields code execution in the service's privileged context, giving the attacker elevated (SYSTEM-level) privileges on the local machine with high impact to confidentiality, integrity, and availability. Any Windows installation running an affected version of the Device Association Service is exposed, though the provided data does not specify which Windows versions or builds are affected, so defenders should confirm exact scope against Microsoft's advisory. Exploitation has not been observed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at just 0.3%.
What to do: Apply the Microsoft monthly cumulative Windows update that addresses CVE-2026-69478 as soon as it is available, prioritizing shared systems where local standard users are less trusted (VDI, kiosks, RDS/terminal hosts, developer workstations). Because the provided data does not list affected builds, verify scope against Microsoft's advisory rather than assuming all Windows versions are affected. No in-the-wild exploitation is currently known, so a standard patch-cycle timeline is defensible, but do not defer beyond the next patch cycle given the high-severity SYSTEM-level impact.
| Microsoft Windows (Device Association Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.