Impact
Spaceport.sys is a Windows kernel device driver used to provide certain system services. The flaw is a heap‑based buffer overflow that can be triggered by a network request from an authorized attacker. Exploiting the overflow could allow an attacker to write arbitrary data into kernel memory, potentially enabling the execution of code with elevated privileges. The weakness is identified as CWE‑122, which indicates that the driver does not perform adequate bounds checking before copying data into a heap buffer. This kind of flaw can compromise the confidentiality, integrity, and availability of the affected system if successfully abused.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, including their Server Core editions. The driver is present in all these releases, so any machine that has the corresponding OS version is susceptible.
Risk and Exploitability
The CVSS score of 8 indicates a high severity vulnerability. The EPSS score is not available, so the current estimate of exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog, suggesting that no confirmed public exploits have been reported yet. The likely attack vector is a network‑based request from an authenticated user who already has remote session or device access, which can be used to trigger the overflow. Because the flaw requires writing to kernel memory, an attacker would need to supply a crafted network payload that triggers the memory corruption in Spaceport.sys. The absence of an active exploit in the wild reduces immediate risk, but the high severity and potential for privilege escalation warrant prompt remediation.
OpenCVE Enrichment