Impact
A heap-based buffer overflow in the Windows Spaceport.sys kernel driver allows an attacker with local or remote authorized network access to gain elevated privileges on the affected system. The vulnerability, classified as CWE-122 and CWE-197, can lead to the execution of code with system privileges, compromising the confidentiality, integrity, and availability of the computer.
Affected Systems
The flaw impacts Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server editions 2016, 2019, 2022, and 2025. Both client and server core installations are affected.
Risk and Exploitability
The CVSS score of 8.0 denotes a high severity flaw. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation at this time. The likely attack vector requires an attacker who is already authorized on the network and can influence the application of the Spaceport.sys driver, implying that systems with wide network exposure or poorly segmented environments would face a higher risk.
OpenCVE Enrichment