Impact
The vulnerability is a use‑after‑free flaw in Windows Autopilot that allows an attacker who already has authorized local access to execute actions with higher privileges. This is linked to CWE-416 and can enable the attacker to gain system‑level rights on the affected machine.
Affected Systems
Microsoft Windows 11 version 24H2 and 25H2 (arm64 architecture) are affected. No other operating systems or versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7 indicates a high severity for local privilege escalation, while the EPSS score of <1% reflects a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but local privileged users can exploit it if the software update that mitigates the use‑after‑free is not applied. The attacker must have an authorized local account; remote exploitation is not indicated in the available data.
OpenCVE Enrichment