ZeroHour

CVE-2026-73009

large

Use-After-Free RCE in Microsoft Windows SSTP VPN Service

CVSS 3.1
9.8 critical
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-73009 is a use-after-free (CWE-416) in the Windows Secure Socket Tunneling Protocol (SSTP), Microsoft's SSL/TLS-based VPN protocol. A remote, unauthenticated attacker can trigger the flaw over the network by connecting to the SSTP service, causing it to reuse freed memory in a way that allows arbitrary code execution. Successful exploitation yields code execution on the target system with the privileges of the SSTP/VPN service, with high impact on confidentiality, integrity, and availability (CVSS 9.8). Systems are affected when the SSTP VPN component is enabled — most commonly Windows machines acting as VPN endpoints via the Routing and Remote Access Service — though the data does not specify exact affected version ranges. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV; EPSS estimates roughly a 0.9% chance of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-73009 as soon as it is available, consulting the Microsoft advisory for the exact affected product/version list. In the interim, inventory for systems with SSTP/RRAS enabled and reduce exposure by blocking or restricting inbound TCP 443 to the SSTP endpoint at the firewall, or fronting it with a patched gateway. Prioritize patching internet-facing VPN servers, since no authentication is required for exploitation.

Affected
Microsoft Windows Secure Socket Tunneling Protocol (SSTP) — VPN service (typically via Routing and Remote Access Service)
Estimated exposure
large≈ tens of thousands of internet-exposed Windows SSTP/RRAS VPN endpoints (unknown share of all Windows installs) — SSTP is an optional VPN server role not enabled by default, so exposure is limited to the subset of Windows systems running RRAS/SSTP and publishing it on TCP 443, which internet-wide scans and typical deployment patterns put in the tens…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.