Executive brief
Windows Device Association Service contains a use-after-free vulnerability that allows a local user with limited access to escalate their privileges to higher system levels. An attacker would need valid credentials on the system to exploit this weakness, which could enable them to gain administrative control and access sensitive data or perform unauthorized administrative actions.
Technical details
A use-after-free vulnerability exists in the Windows Device Association Service where freed memory is accessed after deallocation. The vulnerability is triggered through local access and requires that the attacker already possess valid user credentials (authenticated attack vector). Successful exploitation allows privilege escalation from a lower privilege context to a higher privilege level on the affected system. This vulnerability affects Windows Device Association Service and can be remediated through a security patch from Microsoft.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed