Impact
A stack‑based buffer overflow exists in the Windows Device Association Service. The flaw can be triggered when the service processes input received over the network, giving an authorized attacker the ability to elevate privileges on the affected system. An attacker with authorized network access can send malicious data to the service to trigger the overflow. This vulnerability matches CWE‑121 and would allow the attacker to run code with higher privileges, potentially compromising the entire host if exploited successfully.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server 2012 through 2025, including the server core editions of each release.
Risk and Exploitability
The CVSS score of 8.0 indicates high severity. EPSS is not available, so the likelihood of exploitation cannot be quantified, and the flaw is not listed in the CISA KEV catalog. The attack requires network-level interaction with the Device Association Service and some form of authorized access. The likely attack vector is within a trusted network or local environment where an attacker can communicate with the service, but remote exploitation could be possible if such access is achieved.
OpenCVE Enrichment