CVE-2026-72957
Windows Deployment Services Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.
In plain language
AI Act nowThis Windows Deployment Services security flaw can let someone who already has access to the service run code on your server—if you use Windows Deployment Services, you should update, especially for servers reachable by trusted admin/users.
CVE-2026-72957 is a Windows Deployment Services heap-based buffer overflow (CWE-122) that can lead to remote code execution when an authorized attacker can reach and trigger the affected functionality; it is not listed in CISA KEV and has no public exploit code on record.
What to do now
- Check whether any of your machines are running Windows Deployment Services and record their OS version and build number.
- Compare each affected system’s current build to the vendor’s fixed builds: Windows 10 fixed in 10.0.14393.9512 or 10.0.17763.9245; Windows Server 2012 fixed in 6.2.9200.26349; Windows Server 2012 R2 fixed in 6.3.9600.23397; Windows Server 2016 fixed in 10.0.14393.9512; Windows Server 2019 fixed in 10.0.17763.9245; Windows Server 2022 fixed in 10.0.20348.5622; Windows Server 2025 fixed in 10.0.26100.33438.
- Install the Microsoft update for CVE-2026-72957 (per the update guide) on any affected system as soon as possible.
- After patching, verify the build number changed to a fixed version and confirm Windows Deployment Services functions normally.
- Reduce exposure: restrict network access to the Windows Deployment Services endpoints to only the systems/users that must use them.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-72957 and every CVE in our database. Create a free account — no credit card required.
Create Free Account