Impact
A missing authentication check for a critical Windows Autopilot function enables a local attacker who already has authorized user credentials to modify or tamper with Autopilot configuration or associated device settings. The vulnerability does not provide remote access or privilege escalation beyond the scope of the authenticated user, but it allows intentional alteration of device provisioning data which could affect device behavior or security posture.
Affected Systems
The flaw affects Microsoft Windows 10 version 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2022 and Windows Server 2025 (both standard and Server Core installations). These releases are listed in the Common Platform Enumeration strings included in the advisory.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, reflecting the requirement for an authenticated local user to exploit the flaw. The exploit probability (EPSS) is not available, so no current estimate of likelihood can be supplied. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in widespread active exploitation. Based on the description, the attack vector is inferred to be local with an authorized user, requiring no additional lateral movement or remote access.
OpenCVE Enrichment