Impact
A heap-based buffer overflow exists in Windows Deployment Services that can be triggered by an authorized attacker. The flaw permits the attacker to execute arbitrary code with the privileges of the Deployment Services process. The vulnerability can compromise confidentiality, integrity, and availability of the affected host, potentially allowing full system takeover. This is a typical memory corruption weakness (CWE‑122).
Affected Systems
Microsoft Windows 10 (Version 1607 and 1809), Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025 – including Server Core installations – are impacted. All configurations that enable the Deployment Services role are susceptible.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, reflecting a high severity potential. EPSS data is currently unavailable, and the flaw is not listed in the CISA KEV catalog. Based on the description, the attack vector is local and requires authorized access to the host running Deployment Services. Exploitation would involve crafting a malicious deployment package or client request to trigger the heap overflow, after which arbitrary code would run under the context of the Deployment Services service.
OpenCVE Enrichment