Impact
A use‑after‑free flaw in the Windows Device Association Service allows an attacker who already has local, authorized access to trigger the service and manipulate a freed memory pointer. The flaw enables execution of arbitrary code with the privileges of the Device Association Service, which runs as a system‑level process. As a result, a local attacker can elevate their permissions, potentially gaining full administrative rights on the affected machine. The weakness is classified under CWE‑416.
Affected Systems
The vulnerability impacts Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2019, 2022, and 2025, including both full and Server Core installations. These updates affect x86, x64, and ARM64 architectures as listed by Microsoft’s Common Platform Enumeration strings.
Risk and Exploitability
With a CVSS score of 7.0, the flaw represents a high risk to systems that are not patched. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting that no widespread exploitation has been observed to date. However, the local nature of the attack means that any user with physical or administrative access can potentially exploit the flaw if the Device Association Service is running. This underscores the importance of applying the vendor’s patch promptly.
OpenCVE Enrichment