Vulnerability record · CVE-2018-8476 · published 14 November 2018
CVE-2018-8476: Windows Deployment Services TFTP Server memory corruption RCE
Microsoft · Windows Server 2008
Windows Deployment Services TFTP Server mishandles objects in memory, a buffer overflow (CWE-119) that allows remote code execution. The flaw is network-reachable with no authentication or user interaction, and it affects multiple Windows Server versions including 2008, 2012, 2016 and 2019.
Description
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows Server 2008 R2, Windows 10 Servers.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and very high EPSS make this a high-impact, likely-exploitable server flaw.
What it is
Windows Deployment Services TFTP Server mishandles objects in memory, a buffer overflow (CWE-119) that allows remote code execution. The flaw is network-reachable with no authentication or user interaction, and it affects multiple Windows Server versions including 2008, 2012, 2016 and 2019.
Impact
An unauthenticated remote attacker can execute arbitrary code on the affected server, giving full control of the host at the service's privilege level.
Attack surface
Reached over the network via the WDS TFTP service; the CVSS vector shows AV:N/PR:N/UI:N, so no credentials or user action are required. Any host that can send TFTP traffic to the WDS server can attempt it.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high (0.648, 99.2nd percentile), indicating elevated likelihood of exploitation; references include a Check Point research write-up on the PXE Dust vulnerability.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2018-8476 on all affected Windows Server versions.
- If WDS TFTP is not required, disable or remove the Windows Deployment Services role.
- Restrict network access to the WDS TFTP service to trusted management or deployment subnets only.
- Monitor and patch remaining Windows Server 2008/2008 R2/2012/2012 R2/2016/2019 systems, prioritizing internet- or broadly reachable instances.
Detection
- Monitor WDS TFTP service (UDP 69) traffic for malformed or oversized packets and unexpected request patterns.
- Watch for crashes or restarts of the WDS/TFTP service and related Windows error reporting events.
- Alert on unusual child processes or network connections originating from the WDS service process.
- Review WDS server logs for anomalous client requests from untrusted source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/105774 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1042109 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8476 | PatchVendor Advisory |
| https://research.checkpoint.com/2019/pxe-dust-finding-a-vulnerability-in-windows-servers-deployment-services/ | |
| http://www.securityfocus.com/bid/105774 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1042109 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8476 | PatchVendor Advisory |
| https://research.checkpoint.com/2019/pxe-dust-finding-a-vulnerability-in-windows-servers-deployment-services/ |
Track CVE-2018-8476 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8476), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.