Impact
This vulnerability is a heap-based buffer overflow in the Windows Device Association Service. When an authorized local attacker successfully exploits the overflow, the service can be coerced to execute arbitrary code, resulting in elevation of privileges on the affected system. The weakness is classified as CWE‑122, indicating a lack of proper bounds checking that enables memory corruption leading to code execution.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1, and 26H1; Microsoft Windows Server 2016, 2019, 2022, and 2025 including their Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 reflects a high‑severity impact level. EPSS data is not available, so the likelihood of exploitation cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog. The attack vector is local; an attacker must be able to execute code on the target machine or have legitimate user access to leverage the overflow. Once triggered, the attacker gains higher privileges and can carry out additional malicious actions on the system.
OpenCVE Enrichment