Windows Deployment Services TFTP Server
by Microsoft
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-8476 | Cri | 0.69 | 9.8 | 0.63 | Nov 14, 2018 | A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows… | ||
| CVE-2026-62893 | Cri | 0.64 | 9.8 | 0.02 | Aug 11, 2026 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2019-0603 | Hig | 0.51 | 7.5 | 0.34 | Apr 8, 2019 | A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the… | ||
| CVE-2026-0386 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2024-38138 | Hig | 0.49 | 7.5 | 0.02 | Aug 13, 2024 | Windows Deployment Services Remote Code Execution Vulnerability | ||
| CVE-2024-30036 | Med | 0.42 | 6.5 | 0.02 | May 14, 2024 | Windows Deployment Services Information Disclosure Vulnerability | ||
| CVE-2025-29957 | Med | 0.40 | 6.2 | 0.01 | May 13, 2025 | Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. | ||
| CVE-2025-21347 | Med | 0.39 | 6.0 | 0.01 | Feb 11, 2025 | Windows Deployment Services Denial of Service Vulnerability |
- risk 0.69cvss 9.8epss 0.63
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows…
- risk 0.64cvss 9.8epss 0.02
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
- risk 0.51cvss 7.5epss 0.34
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the…
- risk 0.49cvss 7.5epss 0.01
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.49cvss 7.5epss 0.02
Windows Deployment Services Remote Code Execution Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Deployment Services Information Disclosure Vulnerability
- risk 0.40cvss 6.2epss 0.01
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.
- risk 0.39cvss 6.0epss 0.01
Windows Deployment Services Denial of Service Vulnerability