Executive brief
Windows Device Association Broker is a system service that manages connections between devices on a network. A use-after-free vulnerability allows an authorized attacker to escalate their privileges across the network by exploiting memory management flaws in the service, potentially gaining administrator-level access to affected systems.
Technical details
A use-after-free vulnerability exists in the Windows Device Association Broker service where freed memory is accessed after deallocation, leading to memory corruption. The flaw requires an attacker to be authenticated or have local access to trigger exploitation over a network. By crafting malicious requests to the service, an attacker can corrupt application state and execute arbitrary code with elevated privileges. Patches are available through Microsoft's standard security update channels.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed