Impact
This vulnerability is an out‑of‑bounds read in the Spaceport.sys device driver that can be triggered by an authorized local attacker. The flaw allows the attacker to read memory beyond the intended bounds, resulting in the disclosure of sensitive information stored in the system's memory. The impact is limited to data leakage; there is no evidence of code execution or denial‑of‑service effects.
Affected Systems
Affected by this flaw are Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2, Windows 11 releases 23H2, 24H2, 25H2, and 26H1, and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025. The Spaceport.sys driver is the component that can be exploited on these versions.
Risk and Exploitability
The CVSS base score of 4.7 indicates moderate severity, with no EPSS score available and the vulnerability not listed in the CISA KEV catalog. The likely attack vector is local: an authenticated user with sufficient privileges must be able to interact with the driver in order to trigger the out‑of‑bounds read. No public exploit has been reported, so the likelihood of successful exploitation depends on the attacker’s local privilege level and the presence of the vulnerable driver.
OpenCVE Enrichment