logo

Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability

ID: 1bf3c5b0-873c-5dbc-ba08-b24b8fd21cdd

STIX ID: report--1bf3c5b0-873c-5dbc-ba08-b24b8fd21cdd

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-16

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Microsoft disclosed CVE-2026-0386, an improper access control vulnerability in Windows Deployment Services that exposes Unattend.xml over an unauthenticated RPC channel, allowing an attacker on an adjacent network to steal credentials, inject code, and achieve SYSTEM-level execution during automated OS deployments; Microsoft published a two-phase mitigation plan (immediate registry controls and event logging on January 13, 2026, and disabling hands-free deployment by default in April 2026) and recommends disabling hands-free functionality, applying updates, and migrating to alternate deployment methods.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.