Impact
A heap‑based buffer overflow exists in the Windows Spaceport.sys driver. When an attacker with local authorization can trigger the overflow, the driver can redirect control flow and execute code with elevated privileges, allowing the attacker to gain administrative rights on the affected system.
Affected Systems
Microsoft Windows versions including Windows 10 (1607, 1809, 21H2, 22H2) and Windows 11 (23H2, 24H2, 25H2, 26H1), as well as Windows Server product lines from Server 2012 to Server 2025, both full and core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a medium‑to‑high severity vulnerability. Exploit probability data is unavailable, and the issue is not listed in the CISA KEV catalog. The attack vector is local; an attacker must be able to run code on the host to trigger the overflow, typically by interacting with the Spaceport driver or its associated services. Once the vulnerability is leveraged, privilege escalation to system level is possible.
OpenCVE Enrichment