Impact
A use‑after‑free flaw exists in the Windows Deployment Services TFTP server that lets an unauthorized attacker send crafted packets over the network and execute code on the target system. The vulnerability can be used to run arbitrary code with the privileges of the WDS service, potentially giving the attacker full control of the host and exposing sensitive data.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022 and 2025 (including server‑core installations). All listed OEM releases are affected.
Risk and Exploitability
The CVSS score of 9.8 signifies a critical severity. The EPSS score is 2%, and the vulnerability is not currently listed in CISA KEV. The likely attack vector is through the TFTP port (69) used by the WDS service; an adversary who can reach this port and send a malicious payload can trigger the use‑after‑free and gain code execution on the server.
OpenCVE Enrichment