Impact
A use‑after‑free flaw exists in Windows Deployment Services that permits an unauthorized attacker to execute code on the host, resulting in full remote code execution. The underlying weakness is a classic use‑after‑free defect (CWE‑416), allowing the attacker to leverage memory corruption to override program logic. The description indicates that network input can trigger the flaw, so the attack can be performed over the network without the need for local user privileges.
Affected Systems
Microsoft Windows 10 version 1607 and 1809, and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 – including both normal and Server Core installations – are affected.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity, and the EPSS score is not available, leaving the exploitation probability uncertain. The vulnerability is not yet listed in CISA’s KEV catalog. Attackers likely need to send crafted packets to the WDS service from the network to trigger the use‑after‑free, implying a remote attack vector that does not require local user credentials.
OpenCVE Enrichment