The vulnerability is a CWE-416: Use After Free issue in the Windows Device Association Broker service. Microsoft’s description is direct: “Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.”
An attacker would need local authorized access and would have to successfully win a race condition—an inherently timing-sensitive task—but Microsoft says successful exploitation could result in SYSTEM privileges. In other words, the attacker starts on the machine with limited rights, then attempts to turn a narrow foothold into the keys to the Windows kingdom.
Risk and Microsoft’s assessment
- Severity: Important
- CVSS base score: 7.0
- CVSS temporal score: 6.1
- CVSS vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - CWE: CWE-416
- Publicly disclosed: No
- Exploited: No
- Exploitation assessment: Exploitation Unlikely
- Customer action required: Yes
Microsoft notes that the high attack-complexity rating, AC:H, reflects a specific technical hurdle: “Successful exploitation of this vulnerability requires an attacker to win a race condition.” That does not eliminate risk, particularly on systems where an attacker already has a local account or has gained code execution through another route. Privilege-escalation bugs are frequently most useful as the second act of an intrusion, not the opening scene.
Microsoft also states: “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.”
Affected Windows versions and required updates
Administrators should deploy the applicable update and verify that devices reach the listed fixed build.
| Affected product | Required update | Fixed build |
|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems (x86) | KB5123099 | 10.0.14393.9512 |
| Windows 10 Version 1607 for x64-based Systems | KB5123099 | 10.0.14393.9512 |
| Windows 10 Version 1809 for 32-bit Systems (x86) | KB5122876 | 10.0.17763.9245 |
| Windows 10 Version 1809 for x64-based Systems | KB5122876 | 10.0.17763.9245 |
| Windows 10 Version 21H2 for 32-bit Systems (x86) | KB5122878 | 10.0.19044.7725 |
| Windows 10 Version 21H2 for ARM64-based Systems | KB5122878 | 10.0.19044.7725 |
| Windows 10 Version 21H2 for x64-based Systems | KB5122878 | 10.0.19044.7725 |
| Windows 10 Version 22H2 for 32-bit Systems (x86) | KB5122878 | 10.0.19045.7725 |
| Windows 10 Version 22H2 for ARM64-based Systems | KB5122878 | 10.0.19045.7725 |
| Windows 10 Version 22H2 for x64-based Systems | KB5122878 | 10.0.19045.7725 |
| Windows 11 Version 23H2 for ARM64-based Systems | KB5122880 | 10.0.22631.7582 |
| Windows 11 Version 23H2 for x64-based Systems | KB5122880 | 10.0.22631.7582 |
| Windows 11 Version 24H2 for ARM64-based Systems | KB5124008 | 10.0.26100.9445 |
| Windows 11 Version 24H2 for x64-based Systems | KB5124008 | 10.0.26100.9445 |
| Windows 11 Version 25H2 for ARM64-based Systems | KB5124008 | 10.0.26200.9445 |
| Windows 11 Version 25H2 for x64-based Systems | KB5124008 | 10.0.26200.9445 |
| Windows 11 Version 26H1 for ARM64-based Systems | KB5124012 | 10.0.28000.2954 |
| Windows 11 version 26H1 for x64-based Systems | KB5124012 | 10.0.28000.2954 |
| Windows Server 2016 (Server Core installation) (x64) | KB5123099 | 10.0.14393.9512 |
| Windows Server 2016 (x64) | KB5123099 | 10.0.14393.9512 |
| Windows Server 2019 (Server Core installation) (x64) | KB5122876 | 10.0.17763.9245 |
| Windows Server 2019 (x64) | KB5122876 | 10.0.17763.9245 |
| Windows Server 2022 (Server Core installation) (x64) | KB5122882 | 10.0.20348.5622 |
| Windows Server 2022 (x64) | KB5122882 | 10.0.20348.5622 |
| Windows Server 2025 (Server Core installation) (x64) | KB5122871 | 10.0.26100.33438 |
| Windows Server 2025 (x64) | KB5122871 | 10.0.26100.33438 |
Remediation details
For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512. For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245. For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725. For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725. For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725. For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725. For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582. For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445. For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445. For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954. For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512. For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245. For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622. For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438. For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
What IT teams should do
Prioritize deployment through normal Windows update management processes, then confirm the resulting OS build aligns with the appropriate fixed-build target. Because this is a local elevation-of-privilege flaw, patching should sit alongside the basics that make local access harder to obtain in the first place: least-privilege account design, controlled administrative access, and timely remediation of initial-access vulnerabilities.
The race-condition requirement raises the bar, but it is not a force field. A Windows security patch that blocks a path to SYSTEM is still worth installing before someone gets clever with the stopwatch.
References
- Official MSRC or vendor evidence api.msrc.microsoft.com
- Official MSRC or vendor evidence msrc.microsoft.com
- Official MSRC or vendor evidence api.msrc.microsoft.com