Description
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in Windows Autopilot that allows an attacker who already has authorized local access to execute actions with higher privileges. This is linked to CWE-416 and can enable the attacker to gain system‑level rights on the affected machine.

Affected Systems

Microsoft Windows 11 version 24H2 and 25H2 (arm64 architecture) are affected. No other operating systems or versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 7 indicates a high severity for local privilege escalation, while the EPSS score of <1% reflects a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but local privileged users can exploit it if the software update that mitigates the use‑after‑free is not applied. The attacker must have an authorized local account; remote exploitation is not indicated in the available data.

Generated by OpenCVE AI on August 12, 2026 at 15:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Windows 11 cumulative update for 24H2 and 25H2 that addresses the Autopilot use‑after‑free flaw (see Microsoft Security Advisory).
  • After applying the update, review Autopilot enrollment settings and revoke any unused or unnecessary profiles to limit the attack surface.
  • Enable security auditing for privilege‑elevation events and monitor logs for anomalous activity such as elevated token creation or unexpected system‑level actions.

Generated by OpenCVE AI on August 12, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Title Windows Autopilot Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:40.392Z

Reserved: 2026-07-22T21:30:09.119Z

Link: CVE-2026-65778

cve-icon Vulnrichment

Updated: 2026-08-13T13:42:25.099Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:57.187

Modified: 2026-08-13T17:29:08.230

Link: CVE-2026-65778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:31:00Z

Weaknesses