🟠 High  |  Source: Microsoft Security Response Center


CVE-2026-62747 is an elevation of privilege vulnerability in the Windows Device Association Service, which could allow an attacker to gain higher-level permissions on an affected system. Microsoft has issued an update to this advisory, though the change is limited to an acknowledgement correction with no new technical details or patch changes. As a result, the underlying risk profile of this vulnerability remains unchanged.

Security Architect’s Take: No immediate action is required beyond what was already recommended in the original advisory — ensure Windows systems in your Azure or hybrid environments have the relevant patch applied. Use Azure Update Manager or Microsoft Defender for Cloud’s regulatory compliance dashboard to confirm patch status across your estate.

Original advisory: CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability