Heap-Based Buffer Overflow in Windows Deployment Services Allows Local Code Execution
AI analysis
CVE-2026-72957 is a heap-based buffer overflow (CWE-122) in Microsoft's Windows Deployment Services (WDS), the optional Windows Server role used for network-based operating system deployment such as PXE boot and imaging. The flaw is triggered locally: an authorized, low-privileged attacker sends crafted input to the WDS service, overflowing a heap buffer with no user interaction required. Successful exploitation allows the attacker to execute code locally on the affected server, and the high confidentiality, integrity, and availability ratings combined with the low privilege requirement are consistent with a local elevation-of-privilege outcome. Any organization running the WDS server role on Windows Server is affected; the provided data does not specify which Windows Server versions are impacted. As of the available data the flaw is not known to be exploited: it is absent from CISA KEV, has no public proof-of-concept, carries a low 0.3% EPSS score, and was addressed in Microsoft's September 2026 Patch Tuesday.
What to do: Apply Microsoft's September 2026 security updates (Patch Tuesday) covering Windows Deployment Services on every server with the WDS role installed; no specific KB number or fixed version is provided in the available data. Inventory servers for the role (for example via Server Manager or Get-WindowsFeature WDS) and prioritize patching hosts where low-privileged users can log on locally. Because the attack vector is local and there is no known exploitation, standard patch cadence is likely sufficient, but monitor for the emergence of public PoCs or KEV listings.
Affected
| Microsoft Windows Deployment Services (Windows Server role) | — |
Estimated exposure
largetens of thousands of Windows Servers worldwide with the WDS role installed (estimate); only a small share are internet-exposed — WDS is an opt-in Windows Server role used mainly in enterprise OS-imaging and PXE-deployment environments, so only a small fraction of the very large Windows Server install base — plausibly on the order of 10,000–100,000 systems — runs it,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.