Impact
A use‑after‑free flaw has been found in the Windows Secure Socket Tunneling Protocol (SSTP). The vulnerability allows an attacker who is already authenticated on the system to execute arbitrary code with the privileges of the logged‑on user. The weakness is a classic use‑after‑free error (CWE‑416).
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2012 (including Server Core), 2012 R2 (including Server Core), 2016, 2019, 2022, and 2025. The flaw also impacts the corresponding Server Core installations of the 2012 and 2012 R2 releases.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity local code execution vulnerability, yet the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The flaw is not listed in CISA KEV, suggesting it is not currently publicly exploited. Attackers must have the ability to initiate SSTP communication with the target, which generally requires authenticated or authorized access to the system. By sending a specially crafted SSTP packet, an attacker can trigger the use‑after‑free and execute code under the logged‑on user’s privileges.
OpenCVE Enrichment