CVE-2026-72930
massUse-After-Free in Windows SSTP Allows Authorized Local Code Execution
CVE-2026-72930 is a use-after-free memory-safety flaw (CWE-416) in the Windows Secure Socket Tunneling Protocol (SSTP) component, assigned by Microsoft and rated 7.0 (High) with a local attack vector, low privileges required, and no user interaction. The available data does not describe the exact trigger path, but the flaw arises when SSTP frees memory that is still in use, and the High attack-complexity score suggests a difficult-to-hit timing or state condition. An authorized attacker — one who already holds low-privileged access to the target machine — can leverage the bug to execute code locally, and the High confidentiality, integrity, and availability impacts are consistent with code execution in the context of the SSTP service (i.e., local elevation of privilege). Because SSTP ships in the box with Windows, any Windows system running the affected versions is potentially in scope, with particular relevance to SSTP-based VPN endpoints; the precise version ranges are in Microsoft's advisory but not in this data. There is currently no evidence of exploitation: no public proof-of-concept, no CISA KEV listing, and EPSS estimates only a 0.3% chance of exploitation within 30 days (17th percentile).
What to do: Install the Microsoft security update addressing CVE-2026-72930 (see Microsoft's advisory for the exact affected version ranges, which are not listed in this data). Given the local, low-privilege attack requirement and the absence of known exploitation, patch on a normal monthly-cadence basis, prioritizing multi-user hosts and systems with SSTP/RRAS VPN enabled. As interim mitigation, restrict interactive logon rights on Windows endpoints and servers to trusted users only.
| Microsoft Windows (Secure Socket Tunneling Protocol / SSTP component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.