CVE-2026-62893
9.8Microsoft · Windows
A use after free vulnerability in Windows Deployment Services allows unauthenticated, remote attackers to execute arbitrary code.
Executive summary
A critical use after free vulnerability in Windows Deployment Services affects legacy Windows 10 and Server versions, enabling potential remote code execution.
Vulnerability
The flaw exists within Windows Deployment Services, where a use after free error can be triggered by an unauthenticated attacker. This allows for remote code execution by sending specially crafted requests to the service.
Business impact
With a CVSS score of 9.8, this vulnerability poses a critical risk to organizational infrastructure. Exploitation allows for full system compromise, which may lead to the loss of sensitive data, unauthorized access to critical deployment infrastructure, and the potential for widespread malware propagation.
Remediation
Immediate Action: Deploy the latest security patches from Microsoft to all vulnerable Windows 10 and Windows Server instances.
Proactive Monitoring: Review logs for Windows Deployment Services to identify unexpected service crashes or unauthorized connection attempts.
Compensating Controls: If patching is delayed, restrict access to Windows Deployment Services to authorized network segments only, and employ network segmentation to isolate deployment servers.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability requires immediate attention due to its critical severity and remote exploitability. Administrators should verify the patch status of all legacy servers and workstations listed in the affected versions to ensure protection.