Impact
The vulnerability is a heap‑based buffer overflow in the Windows Device Association Service. An attacker who has local access can exploit the overflow to gain higher privileges, potentially taking full control of the machine. The flaw stems from improper buffer handling (CWE‑122), allowing an overwrite of memory that controls the service’s execution flow.
Affected Systems
Affected versions include multiple Windows 10 releases from 1607 through 22H2, all Windows 11 builds from 23H2 onward, and Windows Server versions from 2016 up to 2025, including both full and Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 places this flaw in the High severity range. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known active exploitation. Attackers must be authenticated on the machine, so the threat is most relevant to local users with sufficient privileges. If exploited, the attacker can elevate to system level, giving full control. It is recommended to apply the Microsoft security update as soon as possible.
OpenCVE Enrichment