Executive brief
OpenSSH for Windows is a remote access tool used by IT administrators to securely manage systems over networks. A use-after-free vulnerability allows an attacker to execute arbitrary code on affected systems without authentication, potentially leading to complete system compromise and unauthorized access to sensitive data.
Technical details
This vulnerability is a use-after-free condition in OpenSSH for Windows that allows an unauthenticated remote attacker to achieve arbitrary code execution. The vulnerability is reachable over the network without requiring prior authentication or user interaction. An attacker can exploit this flaw to gain elevated privileges and execute code with system-level access. The specific root cause and affected component details are not publicly disclosed in the available reference material, but the attack vector is confirmed as network-based and does not require authentication.
Affected products
- Microsoft OpenSSH for Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed