CVE-2025-55677

7.8

Microsoft · Windows

An untrusted pointer dereference vulnerability in the Windows Device Association Broker service allows a local, authenticated attacker to achieve privilege escalation.

Executive summary

An untrusted pointer dereference vulnerability in the Windows Device Association Broker service could allow an authenticated attacker to elevate their privileges to a higher level of authority.

Vulnerability

This flaw is caused by an untrusted pointer dereference within the Windows Device Association Broker service. An attacker must already have local access and valid user privileges to trigger the vulnerability, which then allows for local privilege escalation.

Business impact

Successful exploitation of this vulnerability permits a local user to gain elevated privileges, potentially reaching administrative or system-level access. With a CVSS score of 7.8, this is a high-severity issue, as it compromises the integrity and confidentiality of the host operating system. Unauthorized privilege escalation poses significant risks to internal security boundaries and could facilitate deeper lateral movement within a compromised network.

Remediation

Immediate Action: Apply the latest security updates provided by Microsoft for the affected versions of Windows 11 and Windows Server 2025.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or abnormal behavior originating from the Device Association Broker service.

Compensating Controls: Ensure that local user accounts are restricted to the principle of least privilege, which limits the potential damage an attacker can cause if they successfully exploit local vulnerabilities.

Exploitation status

Public Exploit Available: No — exploit_available is unknown.

Analyst recommendation

This vulnerability represents a significant risk to the security posture of local Windows environments due to the potential for privilege escalation. Administrators should prioritize the deployment of the vendor-supplied patches across all affected Windows 11 and Server 2025 instances to mitigate this risk effectively.

More Microsoft CVEs

Sources