CVE-2026-69488
massUse-after-free privilege escalation in Windows Device Association Service
CVE-2026-69488 is a use-after-free memory-safety flaw (CWE-416) in the Microsoft Windows Device Association Service, the built-in service that handles pairing and association of devices with the system. A local attacker who already holds a valid low-privileged account on the machine can trigger the flaw by causing the service to reference memory that has been freed; per the CVSS vector this requires no user interaction but involves high attack complexity, meaning reliable triggering likely depends on timing or specific system conditions. Successful exploitation lets the attacker execute code in the context of the service, elevating privileges from a standard user to administrative-level control of the local host with high impact on confidentiality, integrity, and availability. Any Windows system running the Device Association Service is affected; the exploit path is local, so remote-only attackers cannot leverage it directly. As of now there is no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
What to do: Apply Microsoft's security update addressing CVE-2026-69488 through your standard cumulative-update process, and verify the deployed update includes the Device Association Service fix. Prioritize patching hosts where untrusted or multiple local users can log on, such as shared workstations, RDP-enabled servers, and VDI images. With no public PoC or known exploitation and low EPSS, routine patch cadence is acceptable, but confirm the fix landed after rollout rather than assuming it is included.
| Microsoft Windows Device Association Service (Windows operating system component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.