CVE-2026-72954 – Windows Deployment Services Remote Code Execution Vulnerability

CVSS 7.5 IMPORTANT Critical - Same Day Deployment

“A successful race-condition attack could turn authorized network access into full code execution, putting the confidentiality, integrity, and availability of affected Windows systems at risk.”

CVE-2026-72954 is a critical use-after-free vulnerability in Windows Deployment Services. An authorized attacker with low privileges could exploit the flaw over a network to execute code. Successful exploitation requires winning a race condition, which increases attack complexity. No user interaction is required. The vulnerability is not publicly disclosed and is not known to be exploited.

Key Details

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-416
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.