Impact
The vulnerability is a use‑after‑free that occurs within the Windows Device Association Service. An authenticated local user can trigger the flaw, allowing the attacker to gain higher privileges on the affected system. The flaw is identified as a race‑condition and use‑after‑free weakness (CWE 362, CWE 416). Because the attack requires local access, the primary risk is elevation of privileges for a malicious actor who already has some form of access to the machine.
Affected Systems
The flaw affects multiple Microsoft Windows client and server releases. Client editions include Windows 10 versions 1607, 1809, 21H2, and 22H2, and Windows 11 versions 23H2, 24H2, 25H2, and 26H1. Server editions include Windows Server 2012 R2, 2016, 2019, 2022, and 2025, both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates high severity, though no EPSS score is available. The flaw is not listed in CISA’s KEV catalog, so no known active exploitation is disclosed. Attackers must have local access to the target system and sufficient privileges to start the Device Association Service; after triggering the use‑after‑free they can elevate privileges. Given the lack of remote vectors and the requirement for local presence, the overall likelihood of exploitation remains moderate.
OpenCVE Enrichment