Junglewise Threat Intelligence

CVE-2026-69390: Microsoft Windows Spaceport.sys out-of-bounds read

CVE-2026-69390 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Spaceport.sys is a system driver used by the Windows operating system for hardware communication. An authorized attacker with local access could exploit an out-of-bounds read vulnerability to disclose sensitive information from kernel memory, potentially exposing system secrets or user data.

Technical details

The vulnerability is an out-of-bounds read in the Windows Spaceport.sys kernel driver. The flaw allows an authenticated local attacker to read memory outside the intended bounds of a buffer, potentially disclosing sensitive kernel or user data. This requires local code execution privileges and physical or logical access to the affected system. The attack vector is local with no network component. A patch is expected from Microsoft through their standard security update process.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats