Impact
The vulnerability is a use‑after‑free flaw in Windows Autopilot that permits an authorized local attacker to elevate privileges. By abusing a freed resource, the attacker can execute code with higher privileges, potentially reaching system or administrative level, and thereby compromising confidentiality, integrity, and availability on the affected device.
Affected Systems
Microsoft Windows 11, versions 24H2 and 25H2 on ARM64 devices.
Risk and Exploitability
The CVSS score of 7 indicates a moderate to high severity. The EPSS score of less than 1% suggests exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. An attacker must be able to run code locally on the device and is already authenticated or authorized; therefore the likely attack vector is local. Exploitation requires triggering the use‑after‑free by interacting with the Autopilot service, a step not documented publicly.
OpenCVE Enrichment