Junglewise Threat Intelligence

CVE-2026-72943: Microsoft Windows Deployment Services use-after-free remote code execution

CVE-2026-72943 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows Deployment Services is a Microsoft Windows component used to deploy operating system images to computers over a network. An authorized attacker can exploit a use-after-free vulnerability in this service to execute arbitrary code remotely, potentially compromising affected systems and expanding an attacker's foothold within an organization.

Technical details

The vulnerability is a use-after-free flaw in Windows Deployment Services that allows remote code execution. The attack requires network access and some level of authorization to the service. An authenticated attacker can exploit this memory safety issue to execute arbitrary code with the privileges of the Deployment Services process, potentially enabling lateral movement or further system compromise. A patch is available through Microsoft security updates.

Affected products

  • Microsoft Windows Deployment Services

Timeline

  • 2026-09-08: disclosed

References

Related threats