Impact
The vulnerability is a use‑after‑free flaw in Windows Device Association Service that allows an attacker with authorized network access to gain elevated privileges on the affected system.
Affected Systems
The flaw impacts multiple Microsoft Windows releases, including Windows 10 1607, 1809, 21H2, 22H2, Windows 11 23H2, 24H2, 25H2, 26H1, and various Windows Server 2012/2012 R2/2016/2019/2022/2025 versions, both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential for success in privilege escalation; however, the EPSS score is unavailable and the vulnerability is not listed in CISA KEV. Attackers would need authorized network connectivity to the Device Association Service and are likely to exploit the flaw locally or remotely, but no public exploit has been reported. In environments where the Device Association endpoints are exposed, the risk is elevated.
OpenCVE Enrichment