CVE-2026-62893

9.8

Microsoft · Windows

A use after free vulnerability in Windows Deployment Services allows unauthenticated, remote attackers to execute arbitrary code.

Executive summary

A critical use after free vulnerability in Windows Deployment Services affects legacy Windows 10 and Server versions, enabling potential remote code execution.

Vulnerability

The flaw exists within Windows Deployment Services, where a use after free error can be triggered by an unauthenticated attacker. This allows for remote code execution by sending specially crafted requests to the service.

Business impact

With a CVSS score of 9.8, this vulnerability poses a critical risk to organizational infrastructure. Exploitation allows for full system compromise, which may lead to the loss of sensitive data, unauthorized access to critical deployment infrastructure, and the potential for widespread malware propagation.

Remediation

Immediate Action: Deploy the latest security patches from Microsoft to all vulnerable Windows 10 and Windows Server instances.

Proactive Monitoring: Review logs for Windows Deployment Services to identify unexpected service crashes or unauthorized connection attempts.

Compensating Controls: If patching is delayed, restrict access to Windows Deployment Services to authorized network segments only, and employ network segmentation to isolate deployment servers.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability requires immediate attention due to its critical severity and remote exploitability. Administrators should verify the patch status of all legacy servers and workstations listed in the affected versions to ensure protection.

More Microsoft CVEs