CVE-2026-62893 – Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
CVSS 9.8
CRITICAL
2 Critical – Same Day Deployment
“This flaw gives an unauthenticated attacker a direct network path to code execution, with no user interaction and low attack complexity.”
CVE-2026-62893 is a remote code execution vulnerability in Windows Deployment Services caused by a use-after-free condition. An unauthenticated attacker could send a specially crafted packet to an affected TFTP service over the network and potentially execute code on the target system. The attack requires no privileges, no authentication, and no user interaction.
Key Details
- Affected Product
- Microsoft Windows 10 1607
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-416
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.