Impact
This vulnerability is an use‑after‑free flaw in the Windows Autopilot feature that allows an authorized attacker to gain elevated local privileges. By inducing the memory corruption, the attacker can execute privileged code on the affected device, enabling actions such as installing malware, modifying system settings, or compromising other user accounts. The weakness is classified as CWE‑416, indicating a security issue involving the incorrect handling of freed memory.
Affected Systems
Windows 11 Version 24H2 and Version 25H2 for ARM64 devices are impacted. These are the operating system releases that lack the necessary patch for the Autopilot use‑after‑free bug. Devices running those versions should be considered vulnerable until the update is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 7, placing it in the medium‑to‑high severity range. The EPSS score is below 1%, suggesting a low probability of immediate exploitation in the wild, and it is not listed in the CISA KEV catalog. Nonetheless, the flaw requires an attacker to have some degree of authorized access to the local system to trigger the use‑after‑free, meaning the risk is confined to privileged users or locally compromised devices.
OpenCVE Enrichment