Impact
This vulnerability is a use‑after‑free flaw in the Windows Device Association Service that allows an attacker who is already authenticated on the target system to gain higher privileges. The flaw can change the control flow of the service after a memory release, resulting in unauthorized code execution with elevated rights. The weakness is identified as CWE‑416 and can be leveraged by anyone able to run code on the local system, potentially giving them unrestricted access to data, files, and system resources.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Microsoft Windows Server 2016, 2019, 2022, and 2025, both standard and Server Core installations. These products run across x86, x64, and ARM64 architectures and are listed in the vendor update guidance.
Risk and Exploitability
The severity rating of 7.0 indicates a high likelihood of impacting system integrity. While an EPSS score is not available, the update advisory does not mark it as a known exploited vulnerability in the KEV catalog. The attack vector is local; an authorized user or a user with the ability to run code locally can trigger the use‑after‑free condition to elevate privileges. The flaw follows a classic memory corruption scenario, requiring only the service context to be compromised to increase privileges.
OpenCVE Enrichment