Impact
A use after free flaw in Windows Autopilot permits an attacker with local authorized access to execute code with elevated privileges, thus raising their power level on the device. This defect, matching CWE‑416, arises from improper handling of a freed memory reference. As a result, an attacker could gain access to the same rights as the privileged user and potentially compromise critical system components, according to the supplied description.
Affected Systems
Microsoft Windows 11 24H2, 25H2 and 26H1 are affected; the arm64 builds for 24H2 and 25H2 and the x64 build for 26H1 contain the vulnerable code.
Risk and Exploitability
The CVSS score of 7 indicates a moderate risk, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalogue. The likely attack path involves an attacker with legitimate local access triggering a misuse of Autopilot configuration, leading to the use‑after‑free and privilege escalation. Based on the description, it is inferred that the attacker must possess authorized local privileges and invoke the Autopilot process to exploit the flaw, but no explicit details of the exact trigger are provided.
OpenCVE Enrichment