ZeroHour

CVE-2026-69397

mass

Use-After-Free RCE in OpenSSH for Windows

CVSS 3.1
7.5 high
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-69397 is a use-after-free (CWE-416) vulnerability in the OpenSSH implementation shipped for Windows, assigned by Microsoft. Triggering requires a network-reachable condition plus user interaction and favorable timing (CVSS: AV:N/AC:H/PR:N/UI:R), which is consistent with an attacker having to induce a user or service into an SSH connection under attacker-controlled conditions before the freed memory is reused. A successful exploit allows an unauthorized attacker to execute arbitrary code on the target with the impact scored as high across confidentiality, integrity, and availability. Any Windows system using the bundled OpenSSH components is potentially affected, with the exact affected version ranges not stated in the available data. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.6% probability of exploitation within 30 days.

What to do: Track Microsoft's advisory and apply the patched OpenSSH for Windows version as soon as it is released, prioritizing internet-facing Windows servers with the OpenSSH Server optional feature enabled. As interim mitigation, disable or remove the built-in OpenSSH client/server on systems that do not need it, and restrict inbound SSH exposure with firewall rules. Because no public PoC exists yet, verify vendor guidance on whether the flaw lies in the client or server component before tuning which hosts to remediate first.

Affected
Microsoft OpenSSH for Windows (Windows-bundled OpenSSH)
Estimated exposure
massorder of hundreds of millions of Windows endpoints ship the OpenSSH client by default (Windows 10 1809+/11), though the share actually exposed via SSH… — The OpenSSH client is included by default on modern Windows 10/11 and Windows Server releases, giving a potential install base in the hundreds of millions, but the data contains no scan or telemetry counts of systems actually using it.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.