Executive brief
Windows Autopilot is a Microsoft service that automates device provisioning and enrollment for enterprise organizations. A use-after-free vulnerability allows an authorized local attacker to execute code with elevated privileges, potentially compromising system security and enabling unauthorized access to sensitive data or system controls.
Technical details
A use-after-free vulnerability exists in Windows Autopilot that permits an authenticated local attacker to escalate privileges. The vulnerability arises from improper memory management where freed memory is accessed after deallocation, allowing an attacker with local access to trigger arbitrary code execution at a higher privilege level. This attack requires prior authorization to the system but no elevated privileges initially. The vulnerability was publicly disclosed on August 11, 2026.
Affected products
- Microsoft Windows Autopilot
Timeline
- 2026-08-11: disclosed