Impact
The vulnerability is an out‑of‑bounds read within the Windows Spaceport.sys driver, which is a CWE‑125 weakness that grants an authenticated local user the ability to execute arbitrary code on the affected system. This flaw allows a user with authorized access to subvert the integrity of the system and potentially gain elevated privileges, resulting in the compromise of confidentiality, integrity, and availability of the host.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; as well as all Windows Server releases from 2012 through 2025, including both standard and Server Core editions. All listed operating systems contain the vulnerable Spaceport.sys component.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact for local attackers. Because the EPSS score is not available and the flaw is not yet listed in the CISA KEV catalog, the exploit likelihood may not be well quantified, but the existence of a local privilege escalation vector combined with widespread deployment suggests elevated risk. An attacker requires legitimate local credentials to exploit the flaw; therefore, restricting privileged account use and applying the vendor patch are the most effective mitigations.
OpenCVE Enrichment