Executive brief
Windows Secure Socket Tunneling Protocol (SSTP) is a built-in remote access component that enables secure VPN connections. A use-after-free vulnerability allows an authorized local user to escalate their privileges and gain system-level control of the affected machine.
Technical details
A use-after-free vulnerability exists in the Windows Secure Socket Tunneling Protocol (SSTP) implementation. The vulnerability requires the attacker to already be authenticated and have local access to the system. An attacker can exploit this memory corruption issue to achieve privilege escalation and obtain SYSTEM-level privileges. The attack vector is local, and the vulnerability requires either an authorized user or local network access to trigger. A security update is available from Microsoft to remediate this issue.
Affected products
- Microsoft Windows (SSTP) <UNKNOWN>
Timeline
- 2026-09-08: disclosed