CVE-2026-73009

9.8

Microsoft · Windows

A use after free vulnerability in the Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthenticated remote attacker to execute arbitrary code.

Executive summary

A critical use after free vulnerability in the Windows Secure Socket Tunneling Protocol (SSTP) allows for unauthenticated remote code execution, posing a severe risk to system integrity.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Windows SSTP implementation. An unauthenticated attacker can trigger this flaw over a network without user interaction to achieve remote code execution.

Business impact

The ability for an unauthenticated attacker to execute code remotely carries a maximum severity impact. With a CVSS score of 9.8, this vulnerability allows for complete compromise of confidentiality, integrity, and availability. Successful exploitation could lead to total system takeover, lateral movement within the network, and significant operational disruption.

Remediation

Immediate Action: Apply the vendor-provided security updates immediately to bring all affected Windows versions to their respective fixed builds (e.g., 10.0.14393.9512 for Windows 10 Version 1607).

Proactive Monitoring: Monitor network traffic for anomalous SSTP connection requests and review system logs for signs of unexpected process execution or service instability.

Compensating Controls: If patching is not immediately feasible, restrict access to the SSTP service via firewall rules or disable the service if it is not required for business operations.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this remote code execution vulnerability and the lack of required authentication, it represents an extreme risk to the environment. Security teams should prioritize patching across all identified Windows platforms as the primary defense. Delaying the application of these updates leaves systems exposed to potential exploitation by sophisticated attackers.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources