ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability
ZDI discloses an unauthenticated use-after-free remote code execution flaw in Windows Deployment Services (CVE-2026-62893, CVSS 7.5).
ZDI advisory ZDI-26-544 describes a use-after-free in Microsoft Windows Server Deployment Services that allows network-adjacent attackers to execute arbitrary code without authentication. Only systems with Windows Deployment Services enabled are vulnerable. The flaw carries a CVSS rating of 7.5 and is tracked as CVE-2026-62893.