Executive brief
Windows Autopilot is a Microsoft service that automates device provisioning for enterprise customers. A use-after-free vulnerability in Autopilot allows an authorized attacker on a local system to execute code with elevated privileges, potentially leading to complete system compromise and lateral movement within a corporate network.
Technical details
A use-after-free vulnerability exists in Windows Autopilot's privilege escalation path. The vulnerability is triggered by an authorized local attacker who can manipulate memory references to access freed objects, allowing arbitrary code execution with elevated privileges. Attack requires local system access and an authenticated user context. No network propagation vector is present. A patch is available from Microsoft Security Response Center.
Affected products
- Microsoft Windows Autopilot <UNKNOWN>
Timeline
- 2026-08-11: disclosed
- 2026-08-11: advisory