Impact
This vulnerability is a use‑after‑free error in Windows Deployment Services that allows an attacker with authorized access to execute arbitrary code over the network. The flaw can be leveraged to take control of the affected system, compromising confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809; Microsoft Windows Server 2012, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2016, Microsoft Windows Server 2016 Server Core installation, Microsoft Windows Server 2019, Microsoft Windows Server 2019 Server Core installation, Microsoft Windows Server 2022, Microsoft Windows Server 2025, and Microsoft Windows Server 2025 Server Core installation. These build variants are affected by the use‑after‑free defect outlined in the advisory.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score of 0.00618 indicates a very low probability of exploitation, though the potential impact remains significant for any organization that runs Windows Deployment Services with network‑available services. The issue is not listed in CISA’s KEV catalog. Attacks would typically require the attacker to be authenticated or have delegated permissions to the Deployment Services service, after which arbitrary code can be executed as the service account.
OpenCVE Enrichment