ZDI-CAN-31889: ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Microsoft Windows Server. Authentication is not required to exploit this vulnerability. However, only systems with Windows Deployment Services enabled are vulnerable. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-62893.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-31889?
The severity of ZDI-CAN-31889 is rated at 80, indicating a high risk level.
How do I fix ZDI-CAN-31889?
To fix ZDI-CAN-31889, apply the latest security updates provided by Microsoft for Windows Deployment Services.
What systems are affected by ZDI-CAN-31889?
ZDI-CAN-31889 affects only installations of Microsoft Windows Server with Windows Deployment Services enabled.
Can ZDI-CAN-31889 be exploited without authentication?
Yes, ZDI-CAN-31889 can be exploited without requiring authentication, allowing network-adjacent attackers to gain access.
What type of attack can ZDI-CAN-31889 facilitate?
ZDI-CAN-31889 can facilitate remote code execution, enabling attackers to execute arbitrary code on affected systems.