Executive brief
Windows Spaceport.sys is a kernel-level driver responsible for system resource management. An out-of-bounds read vulnerability allows an authorized attacker to read sensitive memory regions and disclose information over the network, potentially exposing system credentials or other confidential data.
Technical details
The vulnerability is an out-of-bounds read in the Windows kernel driver Spaceport.sys. The flaw allows an authenticated attacker with local system access to trigger a read of memory outside the intended buffer boundaries, potentially disclosing sensitive kernel information. Network disclosure is possible if an attacker can leverage the leaked information in a secondary attack. The vulnerability requires prior authorization or local access to trigger, limiting its immediate exploitability.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed: CVE-2026-69393 published