TFTP Windows Deployment Services TFTP Server Remote Code Execution Vulnerability (CVE-2026-62893) state 1
Rule ID
1238807
Severity
Critical
Description
A remote unauthenticated attacker can send specially crafted TFTP requests to a Windows Server system running the Windows Deployment Services (WDS) role. Under specific timing conditions involving asynchronous file operations, the service may access memory that has already been released, which can result in remote code execution in the context of the WDS service. The attack is network-based, requires no authentication or user interaction, and targets systems exposing the WDS TFTP service.
Impact
Remote command execution
Recommendation
Update vendor's patch.
IPS Category
DoS attacks
IPS Anomaly Group
N/A
IPS Rule Default Action
Allow
References
Keywords
Windows Server 2012, Windows Server 2016, Windows Server 2019
Date Created
2026/08/12
Last Updated