Impact
The vulnerability in the Windows Spaceport.sys driver allows a local attacker who already has user-level access to bypass authentication checks for a critical function, giving them the ability to perform privileged operations. This missing authentication check makes the driver a gateway for privilege escalation, mapping to CWE‑306 and permitting the attacker to acquire administrative rights on the compromised machine. Based on the description, it is inferred that the attacker must first have local user-level access to the system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025, including both full installations and Server Core variants. The flaw is present in the Spaceport.sys driver across these releases.
Risk and Exploitability
The CVSS score of 7.8 classifies this as a high severity local privilege escalation. The EPSS score of less than 1% indicates that, as of the latest assessment, exploitation attempts are expected to be rare and not widely used. The vulnerability is not listed in the CISA KEV catalog, so no confirmed public exploits are documented. An attacker would need local access to the system and the ability to load or interact with Spaceport.sys to trigger the privileged function, making physical or local compromise the primary precondition for exploitation. Based on the information, the likely attack vector is local compromise requiring the user to load or interact with Spaceport.sys.
OpenCVE Enrichment