TFTP Windows Deployment Services TFTP Server Remote Code Execution Vulnerability (CVE-2026-62893) state 2-F/Flow

Rule ID

1238884

Severity

Critical

Description

A remote unauthenticated attacker can send specially crafted TFTP requests to a Windows Server system running the Windows Deployment Services (WDS) role. Under specific timing conditions involving asynchronous file operations, the service may access memory that has already been released, which can result in remote code execution in the context of the WDS service. The attack is network-based, requires no authentication or user interaction, and targets systems exposing the WDS TFTP service.

Impact

Remote command execution

Recommendation

Update vendor's patch.

IPS Category

DoS attacks

IPS Anomaly Group

N/A

IPS Rule Default Action

Allow

References

CVE-2026-62893

T0866

T1210

Keywords

Windows Server 2012, Windows Server 2016, Windows Server 2019

Date Created

2026/08/28

Last Updated

2026/08/28