Impact
The vulnerability is a use‑after‑free flaw in OpenSSH for Windows, permitting an attacker to execute arbitrary code on the target system without authentication. This allows full compromise of the machine, affecting confidentiality, integrity, and availability. The flaw is categorized as CWE‑416.
Affected Systems
Affected systems include Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025 in both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high‑severity vulnerability. Although EPSS data is not available, the network‑based trigger indicates a remote attack vector. The flaw is not listed in the CISA KEV catalog, suggesting no confirmed wild exploits yet, but arbitrary code execution remains a high‑priority risk that warrants immediate remediation.
OpenCVE Enrichment