Impact
A heap‑based buffer overflow exists in the Windows Device Association Service that permits an authorized local user to gain higher privileges. The flaw allows the attacker to write beyond the bounds of a heap buffer during service processing, enabling execution of arbitrary code with elevated rights. The impact is a local privilege escalation that can jeopardize the confidentiality, integrity, and availability of the affected system. The weakness is classified as CWE‑122.
Affected Systems
Microsoft products affected include Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2016, 2019, 2022, and 2025, respectively. Full details of vulnerable builds are listed in the Microsoft Security Response Center advisory linked in the references.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local privilege escalation. Because the EPSS score is not available, the current probability of exploitation is unknown but could be moderate given the lack of public exploits. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that a legitimate user with local access can trigger the overflow by interacting with the Device Association Service, which is a system service that can be reachable through user‑initiated device association actions. No remote attack surface is publicly documented, so the exploitation window is limited to the local environment and requires authenticated access on the target machine.
OpenCVE Enrichment