Impact
The vulnerability stems from a release of an invalid pointer or reference in the Windows Device service, which is an improper cleanup operation (CWE‑763). An authorized local attacker can exploit this flaw to gain elevated privileges, potentially executing code with administrative rights and compromising system integrity or accessing protected resources.
Affected Systems
Affected Windows editions include Windows 10 from version 1607 through 22H2, Windows 11 from versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2016 and Server 2019 (both full and Server Core). The vulnerability exists across x86, x64 and arm64 builds as indicated by the associated CPE entries.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the lack of an EPSS score suggests no current exploitation data is available. The flaw is not listed in the CISA KEV catalog, yet local privilege escalation remains a valuable objective for threat actors. The attack vector is local and requires an attacker who already has some level of access on the affected machine; exploiting the fault in the Device Association service can elevate privileges. Organisations should verify whether the service is required and consider hardening local permissions pending a vendor patch.
OpenCVE Enrichment