Junglewise Threat Intelligence

CVE-2026-69711: Microsoft Windows Device Association Service use-after-free elevation of privilege

CVE-2026-69711 · Severity: high · CVSS 7 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Windows Device Association Service is a system component that manages connections between Windows devices and external hardware. A use-after-free vulnerability allows an authenticated local user to execute code with elevated system privileges, potentially leading to full system compromise.

Technical details

A use-after-free vulnerability exists in the Windows Device Association Service where memory is accessed after it has been freed. An authorized local attacker can trigger this condition to achieve arbitrary code execution with elevated privileges. The vulnerability requires local access and an authenticated user context. No publicly known exploits are currently documented, though the attack vector is local only.

Affected products

  • Microsoft Windows Device Association Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References