Use After Free Vulnerability in Windows Autopilot by Microsoft
CVE-2026-65778

7HIGH

What is CVE-2026-65778?

A use after free vulnerability within Windows Autopilot enables an authorized attacker to elevate privileges locally, potentially compromising system security and sensitive data. By exploiting this flaw, attackers may gain unauthorized access to resources, making it essential for users to update and patch their systems promptly. For more information, refer to the vendor advisory.

Affected Version(s)

Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.9168

Windows 11 Version 25H2 ARM64-based Systems 10.0.26200.0 < 10.0.26200.9168

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.