Executive brief
Windows Device Association Service, a system component that manages the pairing and communication between Windows devices and peripherals, contains a use-after-free memory vulnerability. An authenticated attacker with local access to the system could exploit this flaw to elevate privileges and gain system-level control, potentially compromising the entire device and any data or services running on it.
Technical details
A use-after-free vulnerability exists in Windows Device Association Service, stemming from improper memory management in the affected code path. The vulnerability requires local access and authenticated user privileges as a precondition for exploitation. An attacker with these prerequisites can trigger the memory management error to cause arbitrary code execution with elevated privileges. Microsoft has released a security update to address this issue; affected organizations should apply the patch promptly.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed