Junglewise Threat Intelligence

CVE-2026-77500: Microsoft Windows Device Association Service privilege escalation

CVE-2026-77500 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Device Association Service contains a memory safety defect that allows a logged-in user with limited permissions to gain administrative access to the system. An attacker who has already obtained valid credentials could exploit this to take full control of the machine and access sensitive data or install malware.

Technical details

The vulnerability is a use-after-free or invalid pointer dereference (CWE-416/CWE-822) in the Windows Device Association Service, a local system service that manages device pairing and association. The flaw allows an authenticated local attacker to trigger the invalid pointer dereference through a crafted request or action, leading to privilege escalation from user to SYSTEM context. Exploitation requires valid logon credentials but does not require user interaction. An attacker with this privilege escalation can execute arbitrary code with system rights, bypass security controls, and access all system resources. Microsoft has released patches to address this vulnerability.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats