Impact
A use‑after‑free flaw in Windows Autopilot allows an authorized attacker to elevate privileges locally. The vulnerability can grant the attacker administrative rights on the compromised machine, undermining system integrity.
Affected Systems
Microsoft Windows 11 version 24H2 and 25H2 on arm64 devices are affected. No other releases or processor families are listed.
Risk and Exploitability
The CVSS base score is 7.0, indicating high severity. The EPSS score of less than 1% shows a very low current likelihood of exploitation, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is local, requiring the attacker to have authorized or administrative access to the target system to trigger the use‑after‑free condition.
OpenCVE Enrichment