Impact
A flaw in Windows Spaceport.sys exists where an out‑of‑bounds read can be triggered by an authorized user, enabling them to run arbitrary code on the affected machine. The vulnerability stems from incorrect bounds checking in the driver, classified as CWE‑125. While the attack requires local access, it grants the attacker a high privilege level when successful, potentially compromising data, system stability, and further lateral movement.
Affected Systems
The vulnerability affects multiple Windows releases: Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1, and 23H2 again; and Windows Server releases 2019, 2022, and 2025, including Server Core installations. All architecture variations reported – x86, x64, and arm64 – are impacted.
Risk and Exploitability
The CVSS baseline of 7 indicates a medium severity with the potential for significant damage if an attacker can authenticate locally or exploit an existing logged‑in session. The EPSS score is not available, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting no widespread exploit activity has been observed to date. Nonetheless, the attack vector is local, requiring an attacker to have authorized access to the target system; as such, privilege escalation or exploitation of a privileged session could be the most effective paths.
OpenCVE Enrichment