Description
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an use‑after‑free flaw in the Windows Autopilot feature that allows an authorized attacker to gain elevated local privileges. By inducing the memory corruption, the attacker can execute privileged code on the affected device, enabling actions such as installing malware, modifying system settings, or compromising other user accounts. The weakness is classified as CWE‑416, indicating a security issue involving the incorrect handling of freed memory.

Affected Systems

Windows 11 Version 24H2 and Version 25H2 for ARM64 devices are impacted. These are the operating system releases that lack the necessary patch for the Autopilot use‑after‑free bug. Devices running those versions should be considered vulnerable until the update is applied.

Risk and Exploitability

The vulnerability has a CVSS score of 7, placing it in the medium‑to‑high severity range. The EPSS score is below 1%, suggesting a low probability of immediate exploitation in the wild, and it is not listed in the CISA KEV catalog. Nonetheless, the flaw requires an attacker to have some degree of authorized access to the local system to trigger the use‑after‑free, meaning the risk is confined to privileged users or locally compromised devices.

Generated by OpenCVE AI on August 12, 2026 at 15:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Windows 11 updates that contain the fix for CVE‑2026‑65781.
  • Use Group Policy or Windows Update settings to enforce automatic updates and ensure devices remain current.
  • Restrict local administrator privileges to only trusted users and monitor Autopilot enrollment actions for suspicious activity.

Generated by OpenCVE AI on August 12, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Title Windows Autopilot Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:41.407Z

Reserved: 2026-07-22T21:30:09.119Z

Link: CVE-2026-65781

cve-icon Vulnrichment

Updated: 2026-08-11T18:13:47.435Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:57.550

Modified: 2026-08-13T17:27:25.690

Link: CVE-2026-65781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:30:56Z

Weaknesses