CVE-2026-69714
massStack Buffer Overflow in Windows Device Association Service Allows Privilege Escalation
CVE-2026-69714 is a stack-based buffer overflow (CWE-121) in the Windows Device Association Service, a built-in Windows component that handles device association and pairing activity. Per the CVSS vector, the flaw is reachable over the network (AV:N) with low attack complexity, but exploitation requires an authorized low-privileged attacker and user interaction (PR:L/UI:R), consistent with a crafted association request that a user or session helps trigger. Successful exploitation allows privilege elevation to the service's elevated context (the service runs with SYSTEM-level rights), yielding high impact on confidentiality, integrity, and availability of the host. It affects Windows installations carrying the Device Association Service; the available data does not enumerate specific affected Windows builds or version ranges. There is no confirmed exploitation so far: no CISA KEV listing, no known public proof-of-concept, and EPSS puts the 30-day exploitation probability at roughly 0.8%.
What to do: Apply Microsoft's security update for CVE-2026-69714 to affected Windows systems as soon as it is available, and check Microsoft's advisory for the exact affected builds since version ranges were not provided here. Because exploitation requires valid low-privileged credentials plus user interaction, prioritize patching user-facing workstations and verify patch deployment afterward. Until patched, monitor for anomalous activity involving the Device Association Service; there is no known public exploit to defend against today.
| Microsoft Windows Device Association Service (Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.