Executive brief
The Windows Device Association Service, a system component that manages device pairing and connections, contains a heap buffer overflow vulnerability. An authorized local attacker can exploit this to gain elevated privileges on the system, potentially gaining administrative control of the compromised machine.
Technical details
A heap-based buffer overflow exists in the Windows Device Association Service, allowing an authenticated local attacker to overflow a heap buffer and achieve privilege escalation. The vulnerability requires local access and authorization, but does not require user interaction. By crafting a malicious input or request to the service, an attacker can overwrite heap memory and execute arbitrary code with elevated SYSTEM privileges. Microsoft has released patches to address this vulnerability.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed