Impact
The exploit allows an out‑of‑bounds read in Spaceport.sys, enabling an attacker who has authorized access to the system to retrieve sensitive data that is normally protected. The consequence is a breach of confidentiality, with the attacker potentially using the disclosed information to further compromise the system or its network. The weakness is classified as a boundary violation (CWE‑125).
Affected Systems
The vulnerability affects multiple Microsoft operating systems. On desktop releases it includes Windows 10 versions 1607, 1809, 21H2 and 22H2, as well as Windows 11 releases 23H2, 24H2, 25H2, 26H1 (and 23H2 is listed twice). On server editions it includes Windows Server 2016, 2019, 2022 and 2025, including their Server Core variants.
Risk and Exploitability
With a CVSS score of 5.7 the vulnerability is considered moderate. EPSS information is not available and the issue is not listed in CISA’s KEV catalog, suggesting that active exploitation is not widespread. The description indicates that an attacker must already have authorized access to the victim machine, which narrows the attack vector to local or remote users with existing credentials; from there the attacker can read sensitive memory over the network. The lack of publicly documented exploits and the moderate severity imply that while the risk is not negligible, it is lower than high‑severity, privilege‑escalating flaws.
OpenCVE Enrichment