Executive brief
Windows Secure Socket Tunneling Protocol (SSTP) is a VPN-like component that secures remote network communications. A use-after-free vulnerability in SSTP allows an attacker on the network to execute arbitrary code on affected systems without authentication, potentially leading to complete system compromise and lateral movement within corporate networks.
Technical details
A use-after-free vulnerability exists in the Windows SSTP implementation, where freed memory is accessed and re-used by an attacker. The vulnerability can be triggered remotely over the network without prior authentication, allowing an unauthenticated attacker to execute arbitrary code with the privileges of the SSTP service. The exact vulnerable component and patch status are not detailed in the available advisory excerpt, but this is a critical remote code execution vulnerability requiring network access to the affected system.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed