Executive brief
Windows Autopilot is a Microsoft service that automates Windows device setup and provisioning in enterprise environments. A use-after-free vulnerability allows an authorized attacker with local access to escalate privileges on an affected system, potentially gaining full administrative control and ability to modify system configuration or access sensitive data.
Technical details
A use-after-free memory vulnerability exists in Windows Autopilot's local processing code. An authorized local attacker can exploit this memory safety issue to execute arbitrary code with elevated privileges. The vulnerability requires local access to the system and the attacker must be already authorized (user-level access sufficient). Successful exploitation enables local privilege escalation to system or administrator level. Patches are expected from Microsoft through their regular security updates.
Affected products
- Microsoft Windows Autopilot
Timeline
- 2026-08-11: disclosed