Privilege Escalation in Windows Device Association Service by Microsoft
CVE-2026-24295
7HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-24295?
A vulnerability exists in the Windows Device Association Service due to improper synchronization during concurrent execution. This issue can be exploited by an authorized attacker to elevate their privileges on affected systems, potentially leading to unauthorized access and control over system resources. The necessity for timely updates and patches is crucial to mitigate risks associated with this vulnerability.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8957
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8511
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7058