CVE-2026-72943
largeUse-After-Free RCE in Microsoft Windows Deployment Services
CVE-2026-72943 is a use-after-free (CWE-416) memory-safety flaw in Windows Deployment Services (WDS), the Windows Server role used to boot and deploy Windows images over the network. An authorized attacker who already holds low-privilege network access can trigger the bug remotely with no user interaction, though the high attack-complexity rating means exploitation depends on favorable timing or memory-layout conditions. Successful exploitation yields remote code execution in the context of the WDS service, with high impact on the confidentiality, integrity, and availability of the affected server. Only organizations that have installed and enabled the WDS role are affected; servers without the role are not exposed. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.6% chance of exploitation within 30 days, so no in-the-wild exploitation is currently known.
What to do: Inventory servers with the WDS role enabled (e.g., Server Manager or Get-WindowsFeature WDS) and apply Microsoft's security update for this CVE as soon as it is released, prioritizing servers reachable by less-trusted network segments. Until patched, restrict network access to WDS/PXE endpoints to trusted imaging and management segments and limit which authenticated accounts can reach the service. Check Microsoft's advisory for the definitive list of affected Windows Server builds and any additional mitigations or workarounds.
| Microsoft Windows Deployment Services (WDS) - Windows Server role | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.