CVE-2026-69693: Windows Device Association Broker Service Elevation of Privilege Vulnerability
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
Other sources
Windows Device Association Broker Service Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized to access the affected Windows system and exploit the issue locally. The provided data does not indicate that it can be exploited remotely or without prior access.
What level of access could successful exploitation provide?
Successful exploitation can elevate an authorized local attacker's privileges. The supplied severity vector indicates high impact to confidentiality, integrity, and availability.
Which systems should be assessed?
Assess Microsoft Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025 systems. The issue is associated with the Windows Device Association Broker service.