Junglewise Threat Intelligence

CVE-2026-65783: Microsoft Windows Autopilot use-after-free privilege escalation

CVE-2026-65783 · Severity: high · CVSS 7 · Published 2026-08-11

Executive brief

Windows Autopilot is a Microsoft deployment service that automates device provisioning for enterprise organizations. A use-after-free vulnerability in this component allows an authorized local attacker to execute code with elevated system privileges, potentially compromising the security of newly provisioned devices and the organizations deploying them.

Technical details

A use-after-free vulnerability exists in Windows Autopilot, a memory safety flaw where the application attempts to access memory that has already been freed. The vulnerability requires an attacker to have local access and authorization to the affected system. Exploitation allows privilege escalation from a standard user context to a higher privilege level, potentially enabling full system compromise. The attack vector is local; no network access or user interaction is required beyond the initial authorized access.

Affected products

  • Microsoft Windows Autopilot

Timeline

  • 2026-08-11: disclosed

References

Related threats