CVE-2026-69866
massUse-after-free in Windows Device Association Service allows local privilege escalation
CVE-2026-69866 is a use-after-free memory-safety flaw (CWE-416) in the Windows Device Association Service, the Windows component responsible for handling device pairing and association. An authorized, already-authenticated local attacker can trigger the flaw by causing the service to free memory that is still in use, a condition reflected in the high attack complexity of the CVSS score. Successful exploitation allows the attacker to elevate privileges locally, with high impact on the confidentiality, integrity, and availability of the affected system; the attack requires only low local privileges and no user interaction. Only Windows systems running the affected service are exposed, and only where untrusted or low-privileged users have local sign-in capability, since the attack vector is local rather than remote. There is currently no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within the next 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69866 through Windows Update as soon as it is available and verify patched builds against Microsoft's advisory, since no specific fixed versions are given in the available data. Until patched, prioritize shared systems where low-privileged users can sign in (RDS hosts, jump servers, multi-user workstations) and restrict interactive logon and Remote Desktop rights to trusted users. Monitor Microsoft's advisory and CISA KEV, as exploitation status could change given the high impact if exploited.
| Microsoft Windows (Device Association Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.