Impact
A use‑after‑free vulnerability exists in the Windows Device Association Service that permits an attacker who already has authorized access to locally elevate their privileges. The flaw is identified as CWE‑416, meaning that the operating system can be tricked into accessing freed memory, leading to unintended changes in process privileges. If successfully exploited, the attacker could gain higher rights than granted, potentially enabling full control over the affected system.
Affected Systems
The vulnerability affects multiple Microsoft products including Windows 10 versions 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1 (both arm64 and x64 builds), as well as Windows Server 2019, Server Core installations, Windows Server 2022, and Windows Server 2025, including their Server Core variants.
Risk and Exploitability
The CVSS score of 7 indicates a high severity. The EPSS score is not available, so the current prediction of exploit probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local: an authenticated user must act on the Device Association Service to trigger the use‑after‑free and gain elevated privileges. No public exploit is reported, but the absence of mitigation information suggests that the flaw could be abused by any user with the appropriate access.
OpenCVE Enrichment