ZeroHour

CVE-2026-69711

mass

Use-After-Free Local Privilege Escalation in Windows Device Association Service

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69711 is a use-after-free (CWE-416) memory-corruption flaw in the Windows Device Association Service (the DasHost service included with Windows). A local attacker who is already authorized on the machine can trigger the flaw by interacting with the service in a way that frees an object still in use, causing exploitable memory corruption. Successful exploitation lets the attacker elevate privileges on the local system, with high impact on confidentiality, integrity, and availability on the host. Any Windows installation that ships the Device Association Service is affected, which by default includes modern Windows client and server editions; Microsoft has not published specific affected version ranges in this data. There are currently no reports of in-the-wild exploitation, no known public proof-of-concept, and a low EPSS score of 0.3% over 30 days.

What to do: Apply Microsoft's cumulative monthly security update addressing CVE-2026-69711 via Windows Update as soon as your change window allows; no specific fixed build or workaround is provided in the available data. Because exploitation requires local access with low privileges, prioritize multi-user hosts, jump boxes, VDI images, and shared workstations where local accounts are less trusted. Re-check KEV/EPSS and vendor advisories periodically, as local privilege escalation bugs in default Windows services are often added to exploit chains after patch release.

Affected
Microsoft Windows Device Association Service (DasHost)
Estimated exposure
mass≈1 billion+ Windows installations (service is present by default on Windows 10/11 and Windows Server) — Microsoft has publicly reported roughly 1.4 billion monthly active Windows 10/11 devices, and the Device Association Service is included and running by default on those releases, so the exposed installed base is effectively the entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.