ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability
ZDI discloses an unauthenticated use-after-free remote code execution flaw in Windows Deployment Services (CVE-2026-62893, CVSS 7.5).
ZDI advisory ZDI-26-544 describes a use-after-free in Microsoft Windows Server Deployment Services that allows network-adjacent attackers to execute arbitrary code without authentication. Only systems with Windows Deployment Services enabled are vulnerable. The flaw carries a CVSS rating of 7.5 and is tracked as CVE-2026-62893.
- Use-after-free in Windows Deployment Services allows unauthenticated RCE
- Attack vector is network-adjacent; no authentication required
- Only servers with WDS role enabled are affected
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-62893 | Pre-auth use-after-free RCE in Microsoft Windows Deployment Services (WDS) Microsoft Windows Deployment Services (WDS) contains a use-after-free memory-safety flaw (CWE-416) that an unauthenticated attacker can trigger by sending crafted network traffic to the WDS service, leading to remote code execution on the target system. The vulnerability affects Windows 10 1607 and 1809 and Windows Server 2012, 2016, 2019, 2022, and 2025 on systems where WDS is deployed, a role typically used for network-based (PXE) operating system imaging. A successful exploit grants the attacker code execution with high confidentiality, integrity, and availability impact, reflected in the critical CVSS 3.1 score of 9.8 with network vector, low complexity, and no privileges or user interaction required. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, although EPSS estimates a 2.7% probability of exploitation within 30 days (85th percentile). The flaw was disclosed alongside Microsoft's record September 2026 Patch Tuesday, which shipped nearly 1,000 fixes including two Windows zero-days. Do: Apply Microsoft's September 2026 (or later) security updates for all affected Windows versions listed in the advisory. Because the vulnerable component is an optional role, audit Windows systems for the presence of Windows Deployment Services; disable the role where it is not needed and restrict network access to WDS/PXE endpoints on systems that require it but are not yet patched. Given the moderate EPSS score and lack of public PoC, prioritize patching internet-facing or shared-network WDS servers first and monitor for exploitation activity. | 9.8 | 3% |
| largeon the order of tens of thousands of WDS-enabled Windows systems worldwide (exact count and internet-exposed share unknown) |
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Microsoft Windows Server. Authentication is not required to exploit this vulnerability. However, only systems with Windows Deployment Services enabled are vulnerable. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-62893.
This source does not provide full text. Read it at zerodayinitiative.com.