CVE-2026-69581
massUse-after-free local privilege escalation in Windows Device Association Service
CVE-2026-69581 is a use-after-free flaw (CWE-416, with a race-condition element per CWE-362) in the Windows Device Association Service (DasHost), the built-in Windows component that handles device pairing and association. It is triggered by a local, already-authenticated user who must win a timing-dependent race (the high attack complexity in the CVSS score reflects this), causing the service to use a freed memory object. An attacker who successfully exploits it gains elevation of privileges locally, running at the service's privilege level with high impact on confidentiality, integrity, and availability. Any Windows installation that includes the Device Association Service is affected; Microsoft has not published affected build ranges in the available data. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS assigns only a 0.2% chance of exploitation within 30 days.
What to do: Check Microsoft's security advisory for the exact affected Windows builds and install the corresponding Windows cumulative update (Patch Tuesday release) on all endpoints and servers. No public workaround or PoC is known, so prioritize limiting untrusted local code execution and verify patch status via Windows Update history; re-assess after the advisory details published.
| Microsoft Windows Device Association Service (DasHost) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-362, CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.