Executive brief
Windows Device Association Service, a system component that manages device pairing and connectivity, contains a use-after-free vulnerability. An authorized local user can exploit this flaw to elevate their privileges to a higher level of system access, potentially allowing them to compromise system security and access sensitive data.
Technical details
This vulnerability is a use-after-free memory safety issue in the Windows Device Association Service. The vulnerability requires local access and authenticated user privileges to exploit. An attacker with existing user-level privileges can trigger the use-after-free condition to execute arbitrary code in the context of a higher-privileged process, achieving privilege escalation. Microsoft has released security updates to address this vulnerability; patches should be applied through standard Windows Update mechanisms.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed