Executive brief
Windows Autopilot is a Microsoft service that automates device provisioning and enrollment for enterprises. A double-free memory corruption vulnerability allows an authorized local attacker to execute arbitrary code with elevated privileges, potentially compromising the entire device and corporate networks it connects to.
Technical details
A double-free vulnerability exists in the Windows Autopilot component, where memory is freed twice during processing of device provisioning requests. The vulnerability requires local access and valid credentials (authorized attacker) to trigger. Successful exploitation allows an attacker to corrupt heap memory and achieve code execution with SYSTEM privileges. A patch is expected to be available from Microsoft's Security Update Guide.
Affected products
- Microsoft Windows Autopilot <UNKNOWN>
Timeline
- 2026-08-11: disclosed