ZeroHour

CVE-2026-77500

mass

Windows Device Association Service invalid-pointer release: local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-77500 is a release-of-invalid-pointer flaw (CWE-763) in the Windows Device Association Service, a built-in Microsoft Windows component that handles device pairing/association. An authorized (authenticated) local attacker can trigger the service to release an invalid pointer, corrupting service memory and elevating privileges on the local machine. Successful exploitation yields high-impact gains for the attacker (read, write, and availability of the system), typically meaning code execution at higher-than-user rights without requiring user interaction. Any Windows installation running the affected Device Association Service is in scope, though the provided data does not enumerate specific Windows versions or builds. As of now there is no evidence of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days (26th percentile).

What to do: Apply Microsoft's security update for CVE-2026-77500 as part of your normal patch cycle, prioritizing shared or multi-user Windows hosts where many local accounts can run code. Consult Microsoft's advisory for the definitive list of affected builds and download the corresponding updates (no KB or build numbers are specified in the source data). Until patched, reduce exposure by restricting local logon and code-execution rights for untrusted users on sensitive machines, and monitor for a public PoC given the currently low exploitation probability.

Affected
Microsoft Windows Device Association Service (component of Microsoft Windows)
Estimated exposure
mass≈1 billion+ Windows installations (Device Association Service is a default Windows component) — The Device Association Service ships by default with Windows client releases, and Windows runs on well over a billion devices worldwide, so the potential installed base is at the mass scale; the exact set of affected builds is unknown from…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-763
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.