ZeroHour

CVE-2026-69693

mass

Use-after-free local privilege escalation in Windows Device Association Broker service

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69693 is a use-after-free memory-safety flaw (CWE-416) in the Windows Device Association Broker service, the Windows component that mediates device association operations. An attacker who already holds a low-privileged, authorized account on the local machine can trigger the bug by causing the service to operate on freed memory; the high attack-complexity rating (AC:H) indicates successful exploitation depends on timing or specific conditions, consistent with a race on the freed object. A successful exploit elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity and availability (CVSS 7.0 High). Any Windows system running the affected service is in scope, although the provided data does not specify which Windows editions or builds are affected, so Microsoft's advisory must be consulted for the exact range. There is currently no sign of exploitation: no public PoC exists, the CVE is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation within 30 days (17th percentile).

What to do: Apply Microsoft's security update for this CVE as soon as it is available; check the MSRC advisory for the exact affected builds and KB article, since no version range is given here. In the meantime, prioritize hosts where low-privileged users can log on locally (shared workstations, jump hosts, RDP/terminal servers), as the flaw requires prior local access. With EPSS at 0.3%, no KEV listing and no public PoC, routine patch-cycle timing is acceptable if an update is not yet published.

Affected
Microsoft Windows (Device Association Broker service)
Estimated exposure
mass≈1 billion+ Windows installations potentially affected (affected edition/build range not yet specified) — The Device Association Broker service ships with Windows, whose global installed base is on the order of a billion devices, but the CVE data does not narrow the affected versions, so this upper-bound estimate reflects the Windows fleet…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.