CVE-2026-77500
massWindows Device Association Service invalid-pointer release: local privilege escalation
CVE-2026-77500 is a release-of-invalid-pointer flaw (CWE-763) in the Windows Device Association Service, a built-in Microsoft Windows component that handles device pairing/association. An authorized (authenticated) local attacker can trigger the service to release an invalid pointer, corrupting service memory and elevating privileges on the local machine. Successful exploitation yields high-impact gains for the attacker (read, write, and availability of the system), typically meaning code execution at higher-than-user rights without requiring user interaction. Any Windows installation running the affected Device Association Service is in scope, though the provided data does not enumerate specific Windows versions or builds. As of now there is no evidence of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days (26th percentile).
What to do: Apply Microsoft's security update for CVE-2026-77500 as part of your normal patch cycle, prioritizing shared or multi-user Windows hosts where many local accounts can run code. Consult Microsoft's advisory for the definitive list of affected builds and download the corresponding updates (no KB or build numbers are specified in the source data). Until patched, reduce exposure by restricting local logon and code-execution rights for untrusted users on sensitive machines, and monitor for a public PoC given the currently low exploitation probability.
| Microsoft Windows Device Association Service (component of Microsoft Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-763
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.