Executive brief
Windows Spaceport.sys is a low-level system driver used by Windows to manage storage operations. A heap-based buffer overflow in this driver allows an authenticated attacker to execute code with elevated privileges on affected systems. This could lead to complete system compromise, data theft, or malware installation.
Technical details
A heap-based buffer overflow exists in Windows Spaceport.sys, a core storage subsystem driver. The vulnerability requires an authorized user with local network access to trigger via a specially crafted request. An attacker exploiting this flaw can achieve privilege escalation from a lower-privileged context to SYSTEM level, allowing arbitrary code execution with kernel privileges. The attack vector spans both local and network access paths for authenticated users. Microsoft has released patches through its standard security update process.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed