Impact
A use‑after‑free flaw in the Windows Device Association Broker service enables an attacker who has network reach to the target machine to cause the service to execute code with elevated privileges. The vulnerability is a classic memory error that frees an object and later uses it, allowing code execution in the context of the privileged service. Once triggered, the attacker can acquire full local system rights, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The flaw affects a broad range of Windows operating systems, including Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Windows Server editions 2016, 2019, 2022 and 2025, including core installations.
Risk and Exploitability
The CVSS score of 7.1 places the issue in the medium‑high severity range. No EPSS data is currently available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that, while feasible, it has not yet been widely exploited. The likely attack vector is remote; an attacker with network access to the target device and the ability to interact with the Device Association Broker service can exploit the use‑after‑free to elevate privileges. The prerequisite of being an authorized user or possessing sufficient network reach means the risk is significant for environments that expose the service to external or internal networks.
OpenCVE Enrichment