CVE-2026-73009: Windows SSTP VPN Critical CVSS 9.8 Remote Code Execution Deep Dive
Disclosed as part of Microsoft’s record-setting September 2026 security release, CVE-2026-73009 is a critical CVSS 9.8 Use-After-Free vulnerability in the Windows Secure Socket Tunneling Protocol (SSTP). The flaw allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on exposed enterprise VPN gateways.
Protocol Mechanics & Use-After-Free Trigger
SSTP encapsulates Point-to-Point Protocol (PPP) traffic inside HTTPS (TCP port 443) tunnels to navigate strict firewall perimeters. When a remote client initiates an SSTP connection, the Windows sstpsvc.dll daemon manages handshake negotiation, certificate validation, and state machine transitions.
During the transmission of a crafted SSTP_MSG_CALL_CONNECT_REQUEST control packet containing an unexpected crypto attribute length, an internal memory pointer referencing the client context block is prematurely freed upon parsing failure. However, subsequent state handlers in sstpsvc.dll continue to write connection status flags to the deallocated pointer, creating an exploitable Use-After-Free condition.
Client (Attacker) Windows SSTP Gateway (Port 443)
│ │
│ ──── TLS 1.3 Handshake ─────────────> │
│ <─── TLS Session Established ──────── │
│ │
│ ──── Malformed SSTP_MSG_CALL_REQ ───> │
│ (Invalid Attribute Length) │
│ ├── Context Pointer Freed in memory
│ └── State Handler Re-accesses Freed Chunk
│ -> Heap Spray & Arbitrary Shellcode Execution
Detection & Telemetry Signatures
Enterprise SOCs can detect SSTP exploitation attempts by monitoring anomalous termination events in the Routing and Remote Access service (RasMan / SstpSvc):
# Sigma Rule: Suspicious SSTP Service Crash & Abnormal Child Process
title: Windows SSTP Gateway Exploitation Attempt (CVE-2026-73009)
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: 'svchost.exe'
ParentCommandLine|contains: 'RasMan'
Image|endswith:
- 'cmd.exe'
- 'powershell.exe'
- 'pwsh.exe'
condition: selection
level: criticalRemediation Guidance
- Apply Microsoft September 2026 Cumulative Update: Install the September 2026 security patch across all Windows Server domain controllers, edge gateways, and RRAS nodes.
- Disable SSTP if Unused: If your organization uses IKEv2 or third-party SSL VPN solutions, disable the SSTP listener in RRAS properties.
- Network Filtering: Ensure RRAS port 443 is not exposed directly to untrusted IP ranges without an intermediary Web Application Firewall (WAF) or DDoS protection layer.