Impact
Spaceport.sys implements memory handling for device initialization and contains a heap‑based buffer overflow. When an attacker supplies crafted input while the driver allocates memory, the overflow can overwrite adjacent heap structures, allowing the attacker to execute arbitrary code. The vulnerability is a classic heap overwrite (CWE‑122) and could give the attacker full control over the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity. The EPSS score of 0.00418 (<1%) indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. However, the attack requires physical access to the machine to trigger the buffer overflow through the Spaceport device, so the risk is highest for systems exposed to untrusted personnel. Once exploited, an attacker can run code with arbitrary privileges on the local machine.
OpenCVE Enrichment