ZeroHour

CVE-2026-69866

mass

Use-after-free in Windows Device Association Service allows local privilege escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69866 is a use-after-free memory-safety flaw (CWE-416) in the Windows Device Association Service, the Windows component responsible for handling device pairing and association. An authorized, already-authenticated local attacker can trigger the flaw by causing the service to free memory that is still in use, a condition reflected in the high attack complexity of the CVSS score. Successful exploitation allows the attacker to elevate privileges locally, with high impact on the confidentiality, integrity, and availability of the affected system; the attack requires only low local privileges and no user interaction. Only Windows systems running the affected service are exposed, and only where untrusted or low-privileged users have local sign-in capability, since the attack vector is local rather than remote. There is currently no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within the next 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69866 through Windows Update as soon as it is available and verify patched builds against Microsoft's advisory, since no specific fixed versions are given in the available data. Until patched, prioritize shared systems where low-privileged users can sign in (RDS hosts, jump servers, multi-user workstations) and restrict interactive logon and Remote Desktop rights to trusted users. Monitor Microsoft's advisory and CISA KEV, as exploitation status could change given the high impact if exploited.

Affected
Microsoft Windows (Device Association Service)
Estimated exposure
mass~1 billion+ Windows installations (service present by default on Windows 10/11 and Windows Server) — Microsoft has reported over 1.4 billion Windows 10/11 devices in use and the Device Association Service is installed by default on modern Windows client and server releases, so the potential install base is on the order of a billion…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.