ZeroHour

CVE-2026-72943

large

Use-After-Free RCE in Microsoft Windows Deployment Services

CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-72943 is a use-after-free (CWE-416) memory-safety flaw in Windows Deployment Services (WDS), the Windows Server role used to boot and deploy Windows images over the network. An authorized attacker who already holds low-privilege network access can trigger the bug remotely with no user interaction, though the high attack-complexity rating means exploitation depends on favorable timing or memory-layout conditions. Successful exploitation yields remote code execution in the context of the WDS service, with high impact on the confidentiality, integrity, and availability of the affected server. Only organizations that have installed and enabled the WDS role are affected; servers without the role are not exposed. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.6% chance of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Inventory servers with the WDS role enabled (e.g., Server Manager or Get-WindowsFeature WDS) and apply Microsoft's security update for this CVE as soon as it is released, prioritizing servers reachable by less-trusted network segments. Until patched, restrict network access to WDS/PXE endpoints to trusted imaging and management segments and limit which authenticated accounts can reach the service. Check Microsoft's advisory for the definitive list of affected Windows Server builds and any additional mitigations or workarounds.

Affected
Microsoft Windows Deployment Services (WDS) - Windows Server role
Estimated exposure
largeon the order of ~100,000 Windows Servers with the WDS role worldwide (estimate; mostly on internal networks, few internet-exposed) — No vendor install counts exist, but WDS is an optional Windows Server imaging/PXE role used mainly by mid-size and large enterprises and education (and often present as the PXE provider behind ConfigMgr), implying a global installed base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.