ZeroHour

CVE-2026-72957

large

Heap-Based Buffer Overflow in Windows Deployment Services Allows Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-72957 is a heap-based buffer overflow (CWE-122) in Microsoft's Windows Deployment Services (WDS), the optional Windows Server role used for network-based operating system deployment such as PXE boot and imaging. The flaw is triggered locally: an authorized, low-privileged attacker sends crafted input to the WDS service, overflowing a heap buffer with no user interaction required. Successful exploitation allows the attacker to execute code locally on the affected server, and the high confidentiality, integrity, and availability ratings combined with the low privilege requirement are consistent with a local elevation-of-privilege outcome. Any organization running the WDS server role on Windows Server is affected; the provided data does not specify which Windows Server versions are impacted. As of the available data the flaw is not known to be exploited: it is absent from CISA KEV, has no public proof-of-concept, carries a low 0.3% EPSS score, and was addressed in Microsoft's September 2026 Patch Tuesday.

What to do: Apply Microsoft's September 2026 security updates (Patch Tuesday) covering Windows Deployment Services on every server with the WDS role installed; no specific KB number or fixed version is provided in the available data. Inventory servers for the role (for example via Server Manager or Get-WindowsFeature WDS) and prioritize patching hosts where low-privileged users can log on locally. Because the attack vector is local and there is no known exploitation, standard patch cadence is likely sufficient, but monitor for the emergence of public PoCs or KEV listings.

Affected
Microsoft Windows Deployment Services (Windows Server role)
Estimated exposure
largetens of thousands of Windows Servers worldwide with the WDS role installed (estimate); only a small share are internet-exposed — WDS is an opt-in Windows Server role used mainly in enterprise OS-imaging and PXE-deployment environments, so only a small fraction of the very large Windows Server install base — plausibly on the order of 10,000–100,000 systems — runs it,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs