Elevation of Privilege Vulnerability in Windows Autopilot by Microsoft
CVE-2026-65781

7HIGH

What is CVE-2026-65781?

A use after free vulnerability in Windows Autopilot could allow an attacker with authorized access to elevate their privileges locally. This flaw poses significant risks as it can enable the execution of arbitrary code with higher privileges than intended, potentially compromising the integrity of the affected system. Users are encouraged to apply the latest patches to protect against this vulnerability.

Affected Version(s)

Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.9168

Windows 11 Version 25H2 ARM64-based Systems 10.0.26200.0 < 10.0.26200.9168

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.