Impact
An out‑of‑bounds read in the Windows Spaceport.sys kernel driver allows an attacker to read memory that should be protected. The flaw enables an unauthorized remote attacker to expose sensitive system data, such as credentials, configuration information or other memory contents, without needing privileged access to the machine. The vulnerability is a classic buffer over‑read that can be triggered through crafted network traffic, resulting in a disclosure of data beyond the intended scope of the driver.
Affected Systems
All recent Windows operating systems that ship with the Spaceport.sys driver are affected. This includes Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and all supported Windows Server releases from 2012 R2 up through 2025. Any installation that contains the driver—whether it is the full desktop image or a server core configuration—is vulnerable, and no specific device or additional firmware requirements are listed.
Risk and Exploitability
The CVSS score of 6.5 rates the vulnerability as moderate severity for information disclosure. No EPSS data is currently available and the issue is not listed in CISA’s KEV catalog, indicating that widespread exploitation has not been observed to date. However, the attack vector is remote and unauthenticated, relying on an attacker who can send a specially crafted packet that activates the vulnerable driver. Because the flaw does not require privileged local access or advanced privileges, the risk of exposure remains significant for any exposed Windows host.
OpenCVE Enrichment