Executive brief
Windows Device Association Service, a system component responsible for managing device pairing and association on Windows systems, contains a use-after-free vulnerability that allows an authorized local user to execute code with elevated privileges. An attacker with local access can exploit this flaw to escalate their account privileges and gain administrative control of the system.
Technical details
A use-after-free vulnerability exists in the Windows Device Association Service, a core Windows system service. The vulnerability allows an authorized local attacker to escalate privileges on the system. The attack vector is local and requires the attacker to already have user-level access to the system. By exploiting the use-after-free condition, an attacker can execute arbitrary code in the context of the privileged service, leading to privilege escalation. Microsoft has released a security update to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed