ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Microsoft Windows Server. Authentication is not required to exploit this vulnerability. However, only systems with Windows Deployment Services enabled are vulnerable. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-62893.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-544?
The severity of ZDI-26-544 is rated at 83, indicating a high risk for exploitation.
How do I fix ZDI-26-544?
To fix ZDI-26-544, ensure that you apply the latest security updates provided by Microsoft for Windows Server.
Who is affected by ZDI-26-544?
ZDI-26-544 affects installations of Microsoft Windows Server that have Windows Deployment Services enabled.
What type of attack is facilitated by ZDI-26-544?
ZDI-26-544 allows network-adjacent attackers to execute arbitrary code remotely.
Is authentication required to exploit ZDI-26-544?
No, authentication is not required to exploit ZDI-26-544.