ZeroHour

CVE-2026-72954

large

Use-After-Free in Microsoft Windows Deployment Services Enables Network RCE

CVSS 3.1
7.5 high
EPSS
<1%p46
Published
()
Modified
AI analysis

CVE-2026-72954 is a use-after-free memory-corruption flaw (CWE-416) in Microsoft Windows Deployment Services (WDS), the Windows Server role used for PXE-based network imaging and OS deployment. A remote attacker who already holds some level of credentials ('authorized attacker', low privileges required) can trigger the flaw with crafted network traffic to the WDS service; the high attack-complexity rating means exploitation depends on memory layout and may not succeed on every attempt. If exploited, the attacker gains arbitrary code execution in the context of the WDS service, with high impacts to confidentiality, integrity, and availability on the affected server. Affected systems are Windows Server installations with the WDS role enabled; specific version ranges were not provided in the available data, so defenders should consult Microsoft's advisory for the exact affected and fixed builds. There is currently no evidence of exploitation: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a ~0.6% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update addressing CVE-2026-72954 for Windows Deployment Services, checking Microsoft's advisory for the exact fixed builds since version ranges were not provided here. In the interim, restrict network access to WDS/PXE endpoints to trusted management segments and scope remediation by identifying which servers have the WDS role installed (e.g., via Server Manager or Get-WindowsFeature WDS). Given the high severity but low current exploitation indicators, prioritize this patch after any critical items but before routine maintenance.

Affected
Microsoft Windows Deployment Services (WDS, Windows Server role)
Estimated exposure
large≈10,000–100,000 Windows Server hosts with the WDS role enabled worldwide; only a small fraction internet-exposed — WDS is an optional Windows Server role used almost exclusively for enterprise PXE/imaging, so deployments concentrate in mid-to-large organizations and are typically internal-facing rather than directly internet-exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.