Neowin Microsoft to Disable Hands-Free Deployment Due to Critical RCE Vulnerability
Article Content
- •Microsoft is disabling hands-free deployment in WDS due to CVE-2026-0386.
- •The vulnerability allows RCE via intercepted Unattend.xml files on adjacent networks.
- •Phase 2 of the security hardening will fully disable hands-free deployment by default.
Microsoft is implementing a two-phase plan to disable the hands-free deployment feature in Windows Deployment Services (WDS) due to a critical remote code execution (RCE) vulnerability, CVE-2026-0386, published on January 13, 2026. This vulnerability allows unauthorized attackers on adjacent networks to intercept sensitive configuration files, leading to potential credential theft and arbitrary code execution. The first phase began in January 2026, advising administrators to block unauthenticated access to Unattend.xml files. In the upcoming second phase, hands-free deployment will be fully disabled by default. The change affects Windows 11 and Server 2025 installations that utilize WDS for automated deployments. Microsoft has clarified that Microsoft Configuration Manager is not impacted by this vulnerability. If no action is taken by April 2026, the hands-free deployment feature will be blocked automatically in the April security update. This move is part of Microsoft's broader efforts to enhance security in their deployment workflows.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Microsoft and CVE-2026-0386 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…