ZeroHour

CVE-2026-69574

mass

Use-After-Free Local Privilege Elevation in Windows Device Association Service

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69574 is a use-after-free memory-corruption flaw (CWE-416) in the Windows Device Association Service, a built-in Windows component. An authorized attacker who already has low-privileged code execution on the local machine can trigger the flaw without user interaction, although the attack requires high complexity. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability (typically resulting in SYSTEM-level access). Any Windows system running the Device Association Service is affected; Microsoft has not disclosed exploitation in the wild, no public proof-of-concept is known, and the EPSS score is low (0.3% chance of exploitation in the next 30 days, 17th percentile).

What to do: Apply Microsoft's security update for CVE-2026-69574 when it is released, prioritizing multi-user hosts such as RDS/session servers and shared workstations where standard local accounts exist, since exploitation requires an authorized local user. Until patched, restrict local standard-user access on sensitive Windows hosts; there is no public PoC or in-the-wild exploitation, and the EPSS probability is low (0.3%).

Affected
Microsoft Windows (Device Association Service)
Estimated exposure
masshundreds of millions of Windows endpoints (the service ships by default on modern Windows client and server installs) — The Device Association Service is a default component of current Windows client and server editions, and Windows runs on well over a billion devices worldwide, so the potentially affected install base is in the hundreds of millions even…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.