Impact
The vulnerability is an out‑of‑bounds read in the Windows Spaceport.sys driver that an attacker with local access and sufficient privileges can exploit to gain elevated permissions. By reading memory past the intended boundary, the attacker can manipulate the driver to elevate privilege, potentially accessing system resources and executing malicious code. This flaw is catalogued as CWE‑125 and results in local privilege escalation.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including the Server Core installation), are affected. The vulnerability applies to both ARM64 and x64 architectures where the Spaceport.sys driver is present.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity. The EPSS score is not available, so exploitation probability cannot be quantified from the data. The vulnerability is not listed in the CISA KEV catalog. The attack is local; an authorized user needs to load or interact with Spaceport.sys. No remote exploitation vector is described, so a local attacker with the appropriate privileges can potentially exploit the flaw to elevate rights within the system.
OpenCVE Enrichment