ZeroHour

CVE-2026-71332

mass

Use-after-free local privilege escalation in Windows SSTP

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

Microsoft fixed a use-after-free vulnerability (CWE-416) in the Windows Secure Socket Tunneling Protocol (SSTP) component, the inbox VPN protocol used for Windows remote-access connections. An authorized (authenticated) local user can trigger the flaw, causing the SSTP implementation to reference memory that has already been freed. Successful exploitation allows the attacker to elevate privileges locally, gaining a higher-privileged (typically SYSTEM) context on the affected machine, with high impact on confidentiality, integrity, and availability. The high attack complexity, low required privileges, and local attack vector yield a CVSS 3.1 score of 7.0 (High); the flaw affects Windows editions that ship the SSTP component, with specific version ranges to be taken from Microsoft's advisory. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only a ~0.3% chance of exploitation within 30 days.

What to do: Apply the Windows security/cumulative update addressing this CVE from Microsoft's advisory as soon as it is available via Windows Update or the Microsoft Update Catalog, and prioritize hosts where low-privileged or untrusted users can log on locally or via RDP, since exploitation requires an authorized local account. No public PoC or in-the-wild exploitation is known and the CVE is not on CISA KEV, so there is no federal remediation deadline, but patching during the regular maintenance cycle is prudent given the high impact of local elevation.

Affected
Microsoft Windows (Secure Socket Tunneling Protocol / SSTP component)
Estimated exposure
mass≈1 billion+ Windows installations carry the affected component (local-vector flaw) — SSTP ships as an inbox component on essentially all Windows client and Windows Server editions, so the potentially affected installed base is on the order of Microsoft's >1.4 billion active Windows devices, though exploitation requires an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.