Junglewise Threat Intelligence

CVE-2026-69574: Microsoft Windows Device Association Service use-after-free privilege escalation

CVE-2026-69574 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

The Windows Device Association Service, a core operating system component responsible for managing device associations and discovery, contains a use-after-free vulnerability that allows an authenticated local user to elevate their privileges to system level. An attacker with a valid local account can exploit this flaw to gain administrative control over the affected system, potentially leading to complete system compromise.

Technical details

A use-after-free vulnerability exists in the Windows Device Association Service, where memory is accessed after it has been freed, causing undefined behavior that can be leveraged for privilege escalation. The vulnerability requires local access and an authenticated user account, but does not require special privileges to trigger. An attacker can craft a malicious request to the service that causes the use-after-free condition, allowing arbitrary code execution in the context of the elevated service process. A security patch is available from Microsoft.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats