Executive brief
Windows Autopilot is Microsoft's service for automated device provisioning and management in enterprise environments. A use-after-free vulnerability allows an authorized local user to elevate their privileges to a higher level of access on the system, potentially enabling them to bypass security controls or access sensitive data.
Technical details
The vulnerability is a use-after-free memory corruption issue in Windows Autopilot. An authorized attacker with local access can trigger the use-after-free condition to achieve local privilege escalation. The attack requires prior authentication and local code execution capability on the affected system. Successful exploitation grants the attacker elevated privileges on the compromised device. A patch is available from Microsoft through their Security Update Guide.
Affected products
- Microsoft Windows Autopilot
Timeline
- 2026-08-11: disclosed