Executive brief
Windows Secure Socket Tunneling Protocol (SSTP) is a VPN tunneling mechanism built into Windows that enables secure remote network connections. A use-after-free vulnerability in SSTP allows an authorized local attacker to execute arbitrary code with elevated privileges, potentially leading to complete system compromise or lateral movement within a corporate network.
Technical details
The vulnerability is a use-after-free flaw in the Windows SSTP implementation, allowing an authorized attacker to execute arbitrary code with local access. The attack requires prior authentication or local system access to exploit. An attacker with sufficient privileges can trigger the use-after-free condition to execute code in the context of the SSTP service, potentially achieving system-level code execution. A patch from Microsoft is expected to address this vulnerability.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed