CVE-2026-72957 – Windows Deployment Services Remote Code Execution Vulnerability
CVSS 7.8
IMPORTANT
Critical - Same Day Deployment
“A heap buffer overflow can turn low-level access into high-impact code execution, putting system confidentiality, integrity, and availability at risk.”
CVE-2026-72957 is a critical heap-based buffer overflow vulnerability (CWE-122) in Windows Deployment Services. An authenticated attacker with low privileges can trigger the vulnerability locally and execute code without requiring user interaction. Although the title describes remote code execution, the attack vector is local; “Remote” refers to the location of the attacker, while exploitation requires code to be executed on the local machine.
Key Details
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-122
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.