ZeroHour

CVE-2026-83940

mass

Use-After-Free Local Privilege Escalation in Windows Device Association Service

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-83940 is a use-after-free memory corruption flaw (CWE-416) in the Windows Device Association Service, a built-in Windows component that handles pairing and association of devices. An authorized attacker with existing low-privilege access on the local machine can trigger the flaw by inducing the service to free an object in memory and then access it again, though the high attack complexity suggests specific timing or conditions are required. Successful exploitation allows the attacker to elevate privileges locally, gaining higher rights on the affected system (high confidentiality, integrity, and availability impact). Any Windows installation running the Device Association Service is affected; the source data does not enumerate specific Windows version ranges. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Apply the Windows security update for CVE-2026-83940 released by Microsoft as soon as it is available for your Windows versions, and verify patch status via your endpoint management or vulnerability scanner. Because exploitation requires local access, prioritize patching shared workstations, RDP/VDI hosts, and systems that untrusted or low-privilege users can access. Until patched, restrict local logon rights on sensitive systems and monitor Microsoft's advisory for updated affected-version details.

Affected
Microsoft Windows (Device Association Service)
Estimated exposure
mass≈1+ billion Windows devices (the service is a default Windows component present on virtually all Windows desktop installs) — The Device Association Service ships with Windows by default, so exposure plausibly scales with the global Windows installed base, commonly estimated at over a billion active devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.