Description
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a double free in the Windows Autopilot component that enables an attacker with authorized local access to obtain elevated privileges on the host system. This weakness corresponds to CWE‑415, indicating a memory management error that can subvert control flow. The malicious actor can trigger the defect by executing an action that the Autopilot service performs, which then frees a memory buffer twice, potentially leading to execution of arbitrary code or privileged operations.

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2, and 26H1 are affected. Version 24H2 and 25H2 run on arm64 architecture, while 26H1 runs on x64. Any systems running these releases with the Autopilot enrollment service enabled are at risk. The vulnerability is identified through the Microsoft security update guide for CVE‑2026‑65780.

Risk and Exploitability

The CVSS score of 7 indicates a medium‑to‑high severity for local privilege escalation. The EPSS score is below 1 %, suggesting a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to have legitimate local authority to run applications and interact with the Autopilot service; no remote trigger is described in the provided data. If these conditions are met, the attacker can gain elevated privileges on the affected machine.

Generated by OpenCVE AI on August 12, 2026 at 16:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Windows update that addresses CVE‑2026‑65780.
  • Disable the Autopilot enrollment service via services.msc or a group policy setting to reduce the attack surface if patch deployment is delayed.
  • Continuously monitor Microsoft security advisories and install any follow‑up patches as they become available.

Generated by OpenCVE AI on August 12, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Title Windows Autopilot Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-415
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:39.842Z

Reserved: 2026-07-22T21:30:09.119Z

Link: CVE-2026-65780

cve-icon Vulnrichment

Updated: 2026-08-12T13:50:22.663Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:57.427

Modified: 2026-08-13T17:28:13.980

Link: CVE-2026-65780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:31:01Z

Weaknesses