Impact
A use‑after‑free flaw in the Windows Device Association Service allows an attacker who already has local access to obtain higher privileges. The flaw arises when the service incorrectly frees memory that is still in use, enabling privilege escalation without additional code execution. The vulnerability is a classic example of CWE‑416 and can lead to the attacker acquiring system‑level rights on the affected machine.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server editions 2019, 2022, and 2025 (both standard and Server Core installations).
Risk and Exploitability
The CVSS score of 7.0 indicates significant impact for a local attacker. EPSS is not available, making it difficult to gauge current exploitation prevalence, but the vulnerability is not currently listed in the CISA KEV catalog. An authorized user could exploit the flaw by triggering the service's memory management bug, potentially granting them full control over the system. The attack vector requires local access and the flaw appears exploitable via normal user operations within the affected services.
OpenCVE Enrichment