Impact
Missing release of a resource after its effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) permits an authorized local attacker to cause a denial of service on the SSTP service. The vulnerability does not provide remote code execution, privilege escalation, or any other impact beyond disrupting SSTP on the affected host.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations. All listed architectures (x86, x64, arm64) are affected.
Risk and Exploitability
The CVSS score of 4.7 indicates a medium severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The attack vector is inferred to be local and requires an authorized user to trigger the resource leakage; therefore external exposure is limited while the host may experience service interruptions for SSTP traffic.
OpenCVE Enrichment