# CVE-2026-62889 — Windows SSTP Service `sstpsvc.dll` Racy Call-Context Reference Drop in `SstpWebReceiveResponseCompletion` → Double Free (RCE)

---

## Summary

| | |
|---|---|
| **Product** | Windows — `sstpsvc.dll` (Secure Socket Tunneling Protocol service) |
| **CVE ID** | CVE-2026-62889 |
| **Impact** | Remote Code Execution (unauthenticated, network) |
| **MSRC severity** | Critical |
| **CVSS** | 8.1 / 7.1 — `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` |
| **CWE** | CWE-415: Double Free (race-triggered) |
| **Delivery** | Network — crafted SSTP-over-HTTPS packets (no auth, no interaction) |
| **KB / Fixed build** | KB5121003 — `sstpsvc.dll` 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `sstpsvc.dll` 10.0.26100.8875 — SHA256 `416df55724c91f99087aa58f8dae317cc9851e8ebf7380ae0ccd9854567321d1` |
| **Post-patch binary** | `sstpsvc.dll` 10.0.26100.9168 — SHA256 `ec9505519769d101b03ea6633b5ee013a08cda64de42249ee977d22a6ace00f6` |
| **Feature flag** | `Feature_1207409977` (also `Feature_2530182457`) — **CFR-gated** |
| **Exploitability** | Exploitation Less Likely; not publicly disclosed; not exploited (per MSRC) |

---

## Product Description

`sstpsvc.dll` implements the Windows **Secure Socket Tunneling Protocol** service,
which tunnels PPP over HTTPS for VPN. It processes HTTP request/response **call
contexts**, each **reference-counted** (a refcount field at context offset `+0xd0`)
and freed when the count reaches zero. The HTTP receive-completion callback
`SstpWebReceiveResponseCompletion` releases the call-context reference
(`DereferenceRefCount(ctx + 0xd0)`), and the disconnect/cleanup paths
(`DisconnectServerHttpCallContext`, `InitiateCallContextCleanup`,
`HttpThreadPoolRequestQueueCallback`) also release it.

---

## Vulnerability Summary

Pre-patch, the call-context reference drop in the receive-completion path was not
adequately synchronized against the disconnect/cleanup path. Under a race (`AC:H`),
the same call-context reference could be dropped **twice** — driving the refcount
below zero and freeing the context twice — a double free that corrupts the service
heap (CWE-415). Because the SSTP service is reachable **over the network without
authentication** (a crafted packet suffices), the double free is a remote
code-execution primitive; Microsoft rates it Critical.

---

## Prerequisites and Constraints

- Network, unauthenticated (`AV:N`, `PR:N`, `UI:N`); `AC:H` — the attacker must win
  the race between receive-completion and disconnect/cleanup.
- Send crafted SSTP-over-HTTPS packets that drive concurrent completion and teardown
  of the same call context.
- Result: the reference-counted call context is freed twice.

---

## Vulnerability Details

### Root Cause

The reference-counted SSTP call context had its reference dropped on both the
receive-completion path and the disconnect/cleanup path without adequate
synchronization, so a race could drop the reference (and free the context) twice.

### The patch (confirmed — diff, .8875 → .9168)

Gated behind `Feature_1207409977`, `SstpWebReceiveResponseCompletion` restructures
the reference drop to use a **null-guarded local** so the call-context reference is
released exactly once per path:

```c
// SstpWebReceiveResponseCompletion (10.0.26100.9168) — PATCHED (from our diff)
// pre : DereferenceRefCount((int *)(ctx + 0xd0));      // dropped on this path unconditionally
// post:
lVar10 = 0;
...
if (/* context still owned on this path */) {
    DereferenceRefCount((int *)(lVar10 + 0xd0));        // single, guarded drop
}
```

The surrounding cleanup (`InitiateCallContextCleanup` /
`DisconnectServerHttpCallContext` / `DereferenceRefCount`) is reworked in concert so
the context is freed once across the completion/disconnect race, closing the double
free.

### Patch Completeness Assessment

**CFR-gated behind `Feature_1207409977`.** The single-drop handling runs only when
the flag is enabled; the original path still ships when disabled. Verify
`Feature_1207409977` is enabled to confirm the fix is live.

---

## Detection Guidance

**Behavioural.** SSTP connections that rapidly race response completion against
disconnect/teardown; double-free / heap-corruption crashes in
`sstpsvc!SstpWebReceiveResponseCompletion` / `DisconnectServerHttpCallContext` on
unpatched/flag-disabled builds. Restrict SSTP/RAS exposure to untrusted networks.

**Config.** The fix is CFR-gated — confirm `Feature_1207409977` is enabled.

---

## References

- MSRC advisory — CVE-2026-62889 (Windows SSTP Remote Code Execution), released 2026-08-11, KB5121003.
- Full binary diff: `/data/patch_diffs/sstpsvc_dll-cve-2026-62889-ghidriff.md`
