Executive brief
A memory safety vulnerability in Windows Device Association Service allows an authorized user to crash the service or execute code with elevated privileges. This could enable an attacker with local access to bypass security controls and take full control of the system, leading to data theft, malware installation, or system compromise.
Technical details
A use-after-free vulnerability exists in the Windows Device Association Service, where freed memory is improperly reused, allowing an attacker to corrupt the service's memory state. The vulnerability requires local authentication and execution context to trigger. An attacker with valid local credentials or who has achieved local code execution can craft specific requests to the Device Association Service to exploit the memory safety issue, leading to denial of service or arbitrary code execution at the service's privilege level (typically SYSTEM). Patches are available from Microsoft.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed