Impact
The flaw is a double free in the Windows Autopilot component that enables an attacker with authorized local access to obtain elevated privileges on the host system. This weakness corresponds to CWE‑415, indicating a memory management error that can subvert control flow. The malicious actor can trigger the defect by executing an action that the Autopilot service performs, which then frees a memory buffer twice, potentially leading to execution of arbitrary code or privileged operations.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1 are affected. Version 24H2 and 25H2 run on arm64 architecture, while 26H1 runs on x64. Any systems running these releases with the Autopilot enrollment service enabled are at risk. The vulnerability is identified through the Microsoft security update guide for CVE‑2026‑65780.
Risk and Exploitability
The CVSS score of 7 indicates a medium‑to‑high severity for local privilege escalation. The EPSS score is below 1 %, suggesting a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to have legitimate local authority to run applications and interact with the Autopilot service; no remote trigger is described in the provided data. If these conditions are met, the attacker can gain elevated privileges on the affected machine.
OpenCVE Enrichment