Impact
The vulnerability is an out-of-bounds read in the Windows Spaceport.sys kernel driver that allows an attacker with local authorized access to read data that the driver should not expose. This out-of-bounds read falls under CWE-125 and results in the disclosure of potentially sensitive information from memory. The CVSS score of 5.5 indicates moderate severity, reflecting that the flaw does not lead to remote code execution but does compromise confidentiality in a local context.
Affected Systems
Windows 10 version 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, Windows Server 2022, and Windows Server 2025 (including Server Core installations).
Risk and Exploitability
The vulnerability is scoped to local environments and requires that the attacker be an authorized user or otherwise have local execution privileges to trigger the out-of-bounds read. Because the EPSS score is below 1% and the flaw is not listed in the CISA KEV catalog, there is currently no evidence of widespread exploitation. The moderate CVSS score highlights that while the impact is significant for confidentiality, the attack vector is limited and mitigated once the official patch is applied.
OpenCVE Enrichment