Description
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use after free flaw in Windows Autopilot permits an attacker with local authorized access to execute code with elevated privileges, thus raising their power level on the device. This defect, matching CWE‑416, arises from improper handling of a freed memory reference. As a result, an attacker could gain access to the same rights as the privileged user and potentially compromise critical system components, according to the supplied description.

Affected Systems

Microsoft Windows 11 24H2, 25H2 and 26H1 are affected; the arm64 builds for 24H2 and 25H2 and the x64 build for 26H1 contain the vulnerable code.

Risk and Exploitability

The CVSS score of 7 indicates a moderate risk, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalogue. The likely attack path involves an attacker with legitimate local access triggering a misuse of Autopilot configuration, leading to the use‑after‑free and privilege escalation. Based on the description, it is inferred that the attacker must possess authorized local privileges and invoke the Autopilot process to exploit the flaw, but no explicit details of the exact trigger are provided.

Generated by OpenCVE AI on August 12, 2026 at 16:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Windows 11 security updates that include the Autopilot patch.
  • Ensure that only authorized and least‑privileged accounts are used to configure and manage Autopilot on the device.
  • Configure device group policies to restrict or audit AutoPilot configuration scripts and enforce proper memory management practices during development.

Generated by OpenCVE AI on August 12, 2026 at 16:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Title Windows Autopilot Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:39.304Z

Reserved: 2026-07-22T21:30:09.119Z

Link: CVE-2026-65779

cve-icon Vulnrichment

Updated: 2026-08-11T18:03:05.009Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:57.310

Modified: 2026-08-13T17:28:44.110

Link: CVE-2026-65779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:31:03Z

Weaknesses