Impact
This vulnerability is a use‑after‑free in the Device Association Broker service. An attacker who can create or otherwise control an authorized session on the local machine can trigger a memory reuse error that results in the service running with elevated privileges. The crash can potentially be used to modify system files or configure services with administrative authority, thereby compromising confidentiality, integrity, or availability of the system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known large‑scale exploitation at this time. Because the flaw requires an authorized local user, the attack vector is local. An attacker could exploit the use‑after‑free to gain privileged code execution, potentially leading to full system compromise. Without a public exploit or exploitation tool, the risk remains elevated for systems that have not applied patches.
OpenCVE Enrichment