← Vulnerability feed

Vulnerability record · CVE-2018-8476 · published 14 November 2018

CVE-2018-8476: Windows Deployment Services TFTP Server memory corruption RCE

Microsoft · Windows Server 2008

Windows Deployment Services TFTP Server mishandles objects in memory, a buffer overflow (CWE-119) that allows remote code execution. The flaw is network-reachable with no authentication or user interaction, and it affects multiple Windows Server versions including 2008, 2012, 2016 and 2019.

9.8 CVSS 3.0 Critical EPSS 65% · top 0.8% CWE-119 · Memory buffer overflow
9.8CVSS 3.0 base score, v2 10.0
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows Server 2008 R2, Windows 10 Servers.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and very high EPSS make this a high-impact, likely-exploitable server flaw.

What it is

Windows Deployment Services TFTP Server mishandles objects in memory, a buffer overflow (CWE-119) that allows remote code execution. The flaw is network-reachable with no authentication or user interaction, and it affects multiple Windows Server versions including 2008, 2012, 2016 and 2019.

Impact

An unauthenticated remote attacker can execute arbitrary code on the affected server, giving full control of the host at the service's privilege level.

Attack surface

Reached over the network via the WDS TFTP service; the CVSS vector shows AV:N/PR:N/UI:N, so no credentials or user action are required. Any host that can send TFTP traffic to the WDS server can attempt it.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high (0.648, 99.2nd percentile), indicating elevated likelihood of exploitation; references include a Check Point research write-up on the PXE Dust vulnerability.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2018-8476 on all affected Windows Server versions.
  • If WDS TFTP is not required, disable or remove the Windows Deployment Services role.
  • Restrict network access to the WDS TFTP service to trusted management or deployment subnets only.
  • Monitor and patch remaining Windows Server 2008/2008 R2/2012/2012 R2/2016/2019 systems, prioritizing internet- or broadly reachable instances.

Detection

  • Monitor WDS TFTP service (UDP 69) traffic for malformed or oversized packets and unexpected request patterns.
  • Watch for crashes or restarts of the WDS/TFTP service and related Windows error reporting events.
  • Alert on unusual child processes or network connections originating from the WDS service process.
  • Review WDS server logs for anomalous client requests from untrusted source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-8476 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-1350Windows DNS Server improper input validation remote code executionWindows DNS servers fail to properly handle certain requests, allowing remote code execution. The flaw is network-reachable, needs no authentication …KEVEPSS 97%analysed9.8CVE-2026-33824Double free in Windows IKE Extension enables remote code executionA double free flaw (CWE-415) exists in the Windows IKE Extension, reachable over the network by an unauthenticated attacker. Successful exploitation …KEVEPSS 1.6%analysed9.8CVE-2025-59287Microsoft WSUS deserialization flaw allows unauthenticated remote code executionWindows Server Update Service (WSUS) deserializes untrusted data, letting an unauthenticated network attacker run code on the server. The flaw is rat…KEVEPSS 100%analysed9.8CVE-2019-0708Microsoft Remote Desktop Services use-after-free remote code executionRemote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending spe…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed9.0CVE-2020-1040Microsoft Hyper-V RemoteFX vGPU input validation remote code executionHyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, allowing remote code …KEVEPSS 7.4%analysed

Source: NIST National Vulnerability Database (record CVE-2018-8476), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.