Impact
A numeric truncation error in the Windows Spaceport.sys kernel driver allows an authorized attacker to execute operations with higher privileges on the local system. By exploiting this flaw, the attacker can bypass driver security checks, potentially gaining full control over the affected machine and its resources.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including Server Core installations).
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating a high severity for local attacks. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly reported exploitation yet. Nonetheless, the flaw is exploitable locally by users with authorized access, making it a serious risk for any machine that can be accessed by a compromised or malicious local account.
OpenCVE Enrichment