Junglewise Threat Intelligence

CVE-2026-65782: Microsoft Windows Autopilot use-after-free privilege escalation

CVE-2026-65782 · Severity: high · CVSS 7 · Published 2026-08-11

Executive brief

Windows Autopilot is Microsoft's service for automated device provisioning and management in enterprise environments. A use-after-free vulnerability allows an authorized local user to elevate their privileges to a higher level of access on the system, potentially enabling them to bypass security controls or access sensitive data.

Technical details

The vulnerability is a use-after-free memory corruption issue in Windows Autopilot. An authorized attacker with local access can trigger the use-after-free condition to achieve local privilege escalation. The attack requires prior authentication and local code execution capability on the affected system. Successful exploitation grants the attacker elevated privileges on the compromised device. A patch is available from Microsoft through their Security Update Guide.

Affected products

  • Microsoft Windows Autopilot

Timeline

  • 2026-08-11: disclosed

References

Related threats