Junglewise Threat Intelligence

CVE-2026-69581: Microsoft Windows Device Association Service use-after-free privilege escalation

CVE-2026-69581 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Device Association Service, a system component that manages the pairing and communication between Windows devices and peripherals, contains a use-after-free memory vulnerability. An authenticated attacker with local access to the system could exploit this flaw to elevate privileges and gain system-level control, potentially compromising the entire device and any data or services running on it.

Technical details

A use-after-free vulnerability exists in Windows Device Association Service, stemming from improper memory management in the affected code path. The vulnerability requires local access and authenticated user privileges as a precondition for exploitation. An attacker with these prerequisites can trigger the memory management error to cause arbitrary code execution with elevated privileges. Microsoft has released a security update to address this issue; affected organizations should apply the patch promptly.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats