Skip to content
Auto-CTI
Back to today
NEW HIGH B2

ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability

B ZDI: Published Advisories · · CVE-2026-62893

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
9.8
EPSS
3%

Affected versions

windows 10 1607 windows 10 1809 windows server 2012

Key insight

The flaw is only exploitable on systems with the WDS role enabled, so the effective attack surface depends heavily on role configuration, and no patch is yet confirmed.

Description

ZDI-26-544 describes a use-after-free vulnerability in Microsoft Windows Deployment Services tracked as CVE-2026-62893 and rated by ZDI with a CVSS of 7.5. A network-adjacent attacker can execute arbitrary code on affected Windows Server installations without prior authentication, provided the WDS role is enabled. Affected are therefore servers that serve as deployment infrastructure for operating system images and expose the WDS service to the network. At the time of publication there is no information about active exploitation, a public exploit, or inclusion in the CISA KEV list.

Risk score

68
cvss base
98.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
113.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
31.00
vendor mismatch penalty
0.00

Path: operational

ESC