CVE-2026-69607
largeUse-after-free RCE in Microsoft Windows Deployment Services
CVE-2026-69607 is a use-after-free memory-safety flaw (CWE-416) in Windows Deployment Services (WDS), the Microsoft Windows Server role used for network-based operating system deployment. An unauthenticated attacker can reach the vulnerable code over the network, though the CVSS vector indicates exploitation requires high attack complexity and some form of user interaction. Successful exploitation allows the attacker to execute arbitrary code in the context of the WDS service on the targeted server, with high impact to confidentiality, integrity, and availability. Only organizations that have installed and enabled the Windows Deployment Services role on Windows Server are affected; servers without the role are not exposed. As of this analysis there is no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.6% probability of exploitation within 30 days.
What to do: Identify Windows Servers running the Windows Deployment Services role and apply the Microsoft update that fixes CVE-2026-69607 (check Microsoft's advisory for the KB matching your Windows Server version). If WDS is enabled but not actively used for imaging, disable the role; if it is in use, restrict network reachability of the WDS/PXE endpoints to management or imaging VLANs. Because no public PoC exists and exploitation requires user interaction, risk is currently low, but monitor Microsoft advisories and the CISA KEV catalog for status changes.
| Microsoft Windows Deployment Services (WDS role for Windows Server) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.