Impact
CVE‑2026‑69488 is a use‑after‑free flaw in the Windows Device Association Service that allows an authorized local user to gain higher privileges on the affected system. The vulnerability enables the attacker to execute code with the service’s credentials, elevating privileges and potentially taking full control of the machine. This weakness is classified as CWE‑416 and requires local access to trigger the exploit.
Affected Systems
The flaw affects a wide range of Microsoft Windows releases, including Windows 10 version 1607, 1809, 21H2, and 22H2; Windows 11 version 23H2, 24H2, 25H2, and 26H1; as well as Windows Server 2012 R2, 2016, 2019, 2022, and 2025, including their core installations. The vulnerability is present across both x86 and x64 architectures, and in ARM64 builds of Windows 11. All builds listed in the Microsoft Security Response Center reference are susceptible.
Risk and Exploitability
The CVSS score of 7.0 categorizes the vulnerability as high, while the absence of an EPSS score suggests that active exploitation has not yet been observed. The weakness is not listed in the CISA Known Exploited Vulnerabilities catalog. Because the flaw resides in a system service and is triggered by a use‑after‑free condition, an attacker must be authenticated on the target operating system to exploit it. The likely attack vector is local privilege escalation via a specially crafted request to the Device Association Service.
OpenCVE Enrichment