Impact
A use‑after‑free flaw in Windows Secure Socket Tunneling Protocol (SSTP) allows an attacker who can run code locally to execute privileged code, effectively upgrading a low‑privileged user account to an administrator or system level account. This breach of integrity grants the attacker full control of the affected machine.
Affected Systems
Microsoft Windows 10 release 1607, 1809, 21H2, 22H2; Windows 10 64‑bit installations; Windows 11 23H2, 24H2, 25H2, 26H1, and 23H2 on ARM64; Windows Server 2016 (including Server Core), 2019 (including Server Core), 2022, and 2025 release versions are all impacted.
Risk and Exploitability
The CVSS score of 7.0 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates a very low, but non-zero, probability of exploitation. The vulnerability is not listed in CISA KEV, which suggests no publicly known exploit has been observed. The likely attack vector is a local authenticated user, implying that the threat is primarily a concern for privileged users or those who can gain local access to the system. Consequently, the risk remains significant for environments that use SSTP or allow local users to access the affected operating systems.
OpenCVE Enrichment