ZeroHour

CVE-2026-69581

mass

Use-after-free local privilege escalation in Windows Device Association Service

CVSS 3.1
7.0 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-69581 is a use-after-free flaw (CWE-416, with a race-condition element per CWE-362) in the Windows Device Association Service (DasHost), the built-in Windows component that handles device pairing and association. It is triggered by a local, already-authenticated user who must win a timing-dependent race (the high attack complexity in the CVSS score reflects this), causing the service to use a freed memory object. An attacker who successfully exploits it gains elevation of privileges locally, running at the service's privilege level with high impact on confidentiality, integrity, and availability. Any Windows installation that includes the Device Association Service is affected; Microsoft has not published affected build ranges in the available data. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS assigns only a 0.2% chance of exploitation within 30 days.

What to do: Check Microsoft's security advisory for the exact affected Windows builds and install the corresponding Windows cumulative update (Patch Tuesday release) on all endpoints and servers. No public workaround or PoC is known, so prioritize limiting untrusted local code execution and verify patch status via Windows Update history; re-assess after the advisory details published.

Affected
Microsoft Windows Device Association Service (DasHost)
Estimated exposure
mass≈1 billion+ Windows installations (Device Association Service ships with modern Windows client and server editions) — The service is a default Windows component, so the exposure follows the overall Windows installed base (publicly estimated at over a billion devices), though only systems where an untrusted local user can run code are practically at risk.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.