Impact
A use‑after‑free flaw in Windows Deployment Services enables an attacker who has legitimate network access to the service to execute arbitrary code. The vulnerability permits the attacker to run code with the privileges of the Windows Deployment Services service, potentially allowing full control over the affected system. This is a critical flaw identified as CWE-416 and would allow the attacker to compromise the confidentiality, integrity, and availability of the host.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, and the following Windows Server releases: 2012, 2012 R2, 2016, 2019, 2022, and 2025, including all Server Core installations, are susceptible to the issue.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact and medium-to-high exploitation likelihood, though the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires an attacker to have authorized network access to a Windows Deployment Services instance, the attack vector is inferred to be network‑based with a need for legitimate credentials or administrative access to the service. Once accessed, the attacker can trigger the use‑after‑free and gain code execution privileges.
OpenCVE Enrichment