Executive brief
Windows Autopilot is a cloud-based system that allows organizations to configure and enroll new Windows devices with minimal IT effort. A missing authentication check in a critical Autopilot function allows an authorized local user to tamper with device configuration or enrollment settings, potentially compromising the security posture of managed devices during deployment.
Technical details
The vulnerability is an authentication bypass in a critical function within Windows Autopilot that permits an authorized local attacker to perform tampering operations without proper credential verification. The attack requires local access to the affected system and can only be exploited by an authenticated user with sufficient privileges. An attacker exploiting this flaw could modify sensitive device configuration, compromise enrollment integrity, or interfere with policy application during the Autopilot deployment process. No evidence of active exploitation in the wild has been reported at the time of publication.
Affected products
- Microsoft Windows Autopilot <UNKNOWN>
Timeline
- 2026-09-08: disclosed