Impact
The vulnerability is a double‐free error in Windows Secure Socket Tunneling Protocol (SSTP). It allows an unauthorized attacker who can send crafted SSTP traffic to a vulnerable Windows system to overwrite memory and execute arbitrary code. The resulting impact is remote code execution on the target machine, with full control over the affected system.
Affected Systems
Affected products are Microsoft Windows 10 (from version 1607 through 22H2), Microsoft Windows 11 (from versions 23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server versions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations. Any system running these operating systems with SSTP enabled is at risk.
Risk and Exploitability
The CVSS score of 8.1 classifies this as a high‑severity vulnerability. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog. The flaw can be exploited over the SSTP protocol without user interaction. Based on common knowledge, the SSTP protocol usually operates over TCP port 443, but this CVE does not explicitly state that, so this inference is tentative. Attacks could therefore target exposed SSTP services from remote locations.
OpenCVE Enrichment