CVE-2026-83940
massUse-After-Free Local Privilege Escalation in Windows Device Association Service
CVE-2026-83940 is a use-after-free memory corruption flaw (CWE-416) in the Windows Device Association Service, a built-in Windows component that handles pairing and association of devices. An authorized attacker with existing low-privilege access on the local machine can trigger the flaw by inducing the service to free an object in memory and then access it again, though the high attack complexity suggests specific timing or conditions are required. Successful exploitation allows the attacker to elevate privileges locally, gaining higher rights on the affected system (high confidentiality, integrity, and availability impact). Any Windows installation running the Device Association Service is affected; the source data does not enumerate specific Windows version ranges. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
What to do: Apply the Windows security update for CVE-2026-83940 released by Microsoft as soon as it is available for your Windows versions, and verify patch status via your endpoint management or vulnerability scanner. Because exploitation requires local access, prioritize patching shared workstations, RDP/VDI hosts, and systems that untrusted or low-privilege users can access. Until patched, restrict local logon rights on sensitive systems and monitor Microsoft's advisory for updated affected-version details.
| Microsoft Windows (Device Association Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.