CVE-2026-69791
massUse-After-Free in Windows Device Association Service (Local Privilege Escalation)
CVE-2026-69791 is a use-after-free memory-safety flaw (CWE-416) in the Windows Device Association Service, a component that ships with and runs in Windows. A local, authorized attacker with low privileges can trigger the flaw and exploit it without any user interaction (CVSS AV:L/PR:L/UI:N), though the high attack complexity (AC:H) means reliable exploitation may depend on specific timing or conditions. Successful exploitation yields a local privilege escalation with high impact on confidentiality, integrity, and availability, typically elevation to highly privileged (e.g., SYSTEM) access on the affected host. All Windows installations running affected versions of the Device Association Service are impacted, but the source data does not enumerate the specific affected Windows releases. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Apply the Microsoft security update addressing CVE-2026-69791 as soon as it is available, checking the Microsoft advisory for the exact affected and fixed Windows builds since they are not specified here. Until patching is complete, prioritize hosts where untrusted or low-privileged local users can sign in (shared workstations, terminal/RDS servers, kiosks), and monitor for publication of proof-of-concept code given that exploitation probability is currently low.
| Microsoft Windows (Device Association Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.