Impact
This vulnerability is a use‑after‑free bug, identified as CWE‑416, in the Windows Secure Socket Tunneling Protocol (SSTP) component. An attacker who can send specially crafted SSTP traffic to a vulnerable host can cause the protocol implementation to reference memory that has already been freed, resulting in execution of arbitrary code. The flaw allows an unauthorized network attacker to run code with the same privileges as the SSTP service, potentially leading to full system compromise.
Affected Systems
Affected operating systems include Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server from 2012 through 2025, both standard and Server Core editions.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity flaw with normal attack complexity. The EPSS score of less than 1% suggests that large‑scale exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over the network, targeting SSTP traffic that typically uses port 443; this inference is based on standard SSTP deployment practices. If exploited, an attacker could execute code on the host with the privileges of the SSTP service, potentially compromising the entire system.
OpenCVE Enrichment