ZeroHour

CVE-2026-69488

mass

Use-after-free privilege escalation in Windows Device Association Service

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69488 is a use-after-free memory-safety flaw (CWE-416) in the Microsoft Windows Device Association Service, the built-in service that handles pairing and association of devices with the system. A local attacker who already holds a valid low-privileged account on the machine can trigger the flaw by causing the service to reference memory that has been freed; per the CVSS vector this requires no user interaction but involves high attack complexity, meaning reliable triggering likely depends on timing or specific system conditions. Successful exploitation lets the attacker execute code in the context of the service, elevating privileges from a standard user to administrative-level control of the local host with high impact on confidentiality, integrity, and availability. Any Windows system running the Device Association Service is affected; the exploit path is local, so remote-only attackers cannot leverage it directly. As of now there is no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's security update addressing CVE-2026-69488 through your standard cumulative-update process, and verify the deployed update includes the Device Association Service fix. Prioritize patching hosts where untrusted or multiple local users can log on, such as shared workstations, RDP-enabled servers, and VDI images. With no public PoC or known exploitation and low EPSS, routine patch cadence is acceptable, but confirm the fix landed after rollout rather than assuming it is included.

Affected
Microsoft Windows Device Association Service (Windows operating system component)
Estimated exposure
massHundreds of millions of Windows endpoints (the service is a default Windows component) — The Device Association Service ships by default with Windows client and server editions, so the plausible exposed base is effectively the entire Windows install base, on the order of 10^8-10^9 devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.