CVE-2026-71332
massUse-after-free local privilege escalation in Windows SSTP
Microsoft fixed a use-after-free vulnerability (CWE-416) in the Windows Secure Socket Tunneling Protocol (SSTP) component, the inbox VPN protocol used for Windows remote-access connections. An authorized (authenticated) local user can trigger the flaw, causing the SSTP implementation to reference memory that has already been freed. Successful exploitation allows the attacker to elevate privileges locally, gaining a higher-privileged (typically SYSTEM) context on the affected machine, with high impact on confidentiality, integrity, and availability. The high attack complexity, low required privileges, and local attack vector yield a CVSS 3.1 score of 7.0 (High); the flaw affects Windows editions that ship the SSTP component, with specific version ranges to be taken from Microsoft's advisory. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only a ~0.3% chance of exploitation within 30 days.
What to do: Apply the Windows security/cumulative update addressing this CVE from Microsoft's advisory as soon as it is available via Windows Update or the Microsoft Update Catalog, and prioritize hosts where low-privileged or untrusted users can log on locally or via RDP, since exploitation requires an authorized local account. No public PoC or in-the-wild exploitation is known and the CVE is not on CISA KEV, so there is no federal remediation deadline, but patching during the regular maintenance cycle is prudent given the high impact of local elevation.
| Microsoft Windows (Secure Socket Tunneling Protocol / SSTP component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.