Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability
ID: 1bf3c5b0-873c-5dbc-ba08-b24b8fd21cdd
STIX ID: report--1bf3c5b0-873c-5dbc-ba08-b24b8fd21cdd
Feed Name: cybersecurityNews.com
Microsoft disclosed CVE-2026-0386, an improper access control vulnerability in Windows Deployment Services that exposes Unattend.xml over an unauthenticated RPC channel, allowing an attacker on an adjacent network to steal credentials, inject code, and achieve SYSTEM-level execution during automated OS deployments; Microsoft published a two-phase mitigation plan (immediate registry controls and event logging on January 13, 2026, and disabling hands-free deployment by default in April 2026) and recommends disabling hands-free functionality, applying updates, and migrating to alternate deployment methods.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
