ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- CVSS
- 9.8
- EPSS
- 3%
Affected versions
Key insight
The flaw is only exploitable on systems with the WDS role enabled, so the effective attack surface depends heavily on role configuration, and no patch is yet confirmed.
Description
ZDI-26-544 describes a use-after-free vulnerability in Microsoft Windows Deployment Services tracked as CVE-2026-62893 and rated by ZDI with a CVSS of 7.5. A network-adjacent attacker can execute arbitrary code on affected Windows Server installations without prior authentication, provided the WDS role is enabled. Affected are therefore servers that serve as deployment infrastructure for operating system images and expose the WDS service to the network. At the time of publication there is no information about active exploitation, a public exploit, or inclusion in the CISA KEV list.
Risk score
- cvss base
- 98.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 15.00
- raw before weight
- 113.00
- industry weight
- 1.21
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 31.00
- vendor mismatch penalty
- 0.00
Path: operational