Impact
A heap‑based buffer overflow in the Windows Spaceport.sys driver enables an attacker to execute arbitrary code with kernel privileges. The vulnerability occurs when the driver processes malicious input, allowing the attacker to hijack the system’s highest privilege level. This flaw directly compromises system integrity and confidentiality, granting the attacker unrestricted control over the host.
Affected Systems
The change impacts a broad array of Microsoft Windows platforms: Windows 10 1607, 1809, 21H2, and 22H2; Windows 11 23H2, 24H2, 25H2, and 26H1; and all Windows Server releases from 2012 through 2025 in both standard and Server Core editions. All affected versions rely on the Spaceport.sys kernel driver.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate to high severity, while the EPSS score of < 1% suggests limited likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The flaw requires an attacker to trigger the driver with specially crafted data, which in practice implies physical or direct access to the target system. Once an exploit is triggered, the attacker gains full kernel control.
OpenCVE Enrichment