CVE-2026-69693
massUse-after-free local privilege escalation in Windows Device Association Broker service
CVE-2026-69693 is a use-after-free memory-safety flaw (CWE-416) in the Windows Device Association Broker service, the Windows component that mediates device association operations. An attacker who already holds a low-privileged, authorized account on the local machine can trigger the bug by causing the service to operate on freed memory; the high attack-complexity rating (AC:H) indicates successful exploitation depends on timing or specific conditions, consistent with a race on the freed object. A successful exploit elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity and availability (CVSS 7.0 High). Any Windows system running the affected service is in scope, although the provided data does not specify which Windows editions or builds are affected, so Microsoft's advisory must be consulted for the exact range. There is currently no sign of exploitation: no public PoC exists, the CVE is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation within 30 days (17th percentile).
What to do: Apply Microsoft's security update for this CVE as soon as it is available; check the MSRC advisory for the exact affected builds and KB article, since no version range is given here. In the meantime, prioritize hosts where low-privileged users can log on locally (shared workstations, jump hosts, RDP/terminal servers), as the flaw requires prior local access. With EPSS at 0.3%, no KEV listing and no public PoC, routine patch-cycle timing is acceptable if an update is not yet published.
| Microsoft Windows (Device Association Broker service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.