Impact
The vulnerability is a use–after–free flaw in the Windows Device Association Service, allowing an attacker with local access to manipulate freed memory references and execute code at elevated privileges. This weakness, identified as CWE‑416, can lead to full system compromise once exploited.
Affected Systems
Affected versions include multiple Windows 10 releases (1607 through 22H2), Windows 11 releases (23H2, 24H2, 25H2, 26H1), and Windows Server editions of 2016, 2019, 2022, and 2025, both full and Server Core installations. The service is present on x86/x64 and ARM64 architectures as listed by the CPE identifiers.
Risk and Exploitability
The CVSS score of 7.0 indicates a moderate to high severity. The EPSS score of 0.00252 (less than 1%) indicates a very low probability of exploitation. The absence from the CISA KEV catalog suggests no known active exploits. Based on the description, the attack requires local access to the machine and the ability to interact with the Device Association Service, implying that an authenticated or compromised user account could launch the exploit. With no publicly known exploit, the risk remains opportunistic for threat actors with local access.
OpenCVE Enrichment