CVE-2025-55677: Windows Device Association Broker Service Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
Other sources
Windows Device Association Broker Service Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55677?
CVE-2025-55677 is classified as an elevation of privilege vulnerability affecting Windows Device Association Broker service.
How do I fix CVE-2025-55677?
To fix CVE-2025-55677, apply the updates provided in the Microsoft support documentation related to this vulnerability.
Which products are affected by CVE-2025-55677?
CVE-2025-55677 affects specific versions of Windows 11 and Windows Server 2025, including both x86_64 and arm64 architectures.
Who can exploit CVE-2025-55677?
CVE-2025-55677 can be exploited by an authorized attacker with local access to the system to escalate privileges.
What is the potential impact of CVE-2025-55677?
The potential impact of CVE-2025-55677 is the elevation of privileges, which could allow attackers to execute arbitrary code with elevated rights.