Executive brief
The Windows Device Association Broker service contains a use-after-free memory vulnerability that allows an authenticated local attacker to escalate privileges and gain system-level access. An attacker with standard user credentials can exploit this flaw to take complete control of the affected Windows system, potentially leading to unauthorized system modifications, data theft, or malware installation.
Technical details
This is a use-after-free vulnerability in the Windows Device Association Broker service, a local Windows system service. The vulnerability allows an authenticated attacker with local access to trigger a memory corruption condition that results in privilege escalation from standard user to SYSTEM level. The attack requires local access and prior authentication (standard user credentials), making it a post-compromise escalation vector. An attacker exploiting this flaw can execute arbitrary code with SYSTEM privileges. A patch is available from Microsoft as documented in the Security Update Guide.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed