ZeroHour

CVE-2026-69791

mass

Use-After-Free in Windows Device Association Service (Local Privilege Escalation)

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69791 is a use-after-free memory-safety flaw (CWE-416) in the Windows Device Association Service, a component that ships with and runs in Windows. A local, authorized attacker with low privileges can trigger the flaw and exploit it without any user interaction (CVSS AV:L/PR:L/UI:N), though the high attack complexity (AC:H) means reliable exploitation may depend on specific timing or conditions. Successful exploitation yields a local privilege escalation with high impact on confidentiality, integrity, and availability, typically elevation to highly privileged (e.g., SYSTEM) access on the affected host. All Windows installations running affected versions of the Device Association Service are impacted, but the source data does not enumerate the specific affected Windows releases. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Apply the Microsoft security update addressing CVE-2026-69791 as soon as it is available, checking the Microsoft advisory for the exact affected and fixed Windows builds since they are not specified here. Until patching is complete, prioritize hosts where untrusted or low-privileged local users can sign in (shared workstations, terminal/RDS servers, kiosks), and monitor for publication of proof-of-concept code given that exploitation probability is currently low.

Affected
Microsoft Windows (Device Association Service)
Estimated exposure
masshundreds of millions of Windows endpoints (service ships and runs by default on Windows 10/11-class client and server releases) — The Device Association Service is present by default on broadly deployed modern Windows releases, and Microsoft has publicly reported over 1.4 billion active Windows 10/11 devices, although the affected version range is not enumerated in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.