Junglewise Threat Intelligence

CVE-2026-69535: Microsoft Windows Spaceport.sys privilege escalation

CVE-2026-69535 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Spaceport.sys is a Windows kernel component responsible for GPU memory management. A numeric truncation error in this component allows an authorized local attacker to escape privilege boundaries and gain elevated system access, potentially compromising the entire machine.

Technical details

A numeric truncation vulnerability exists in Windows Spaceport.sys, a kernel-mode driver handling GPU/graphics memory operations. The flaw allows an authenticated local attacker to bypass privilege validation through integer truncation, resulting in arbitrary kernel-level code execution. Exploitation requires local access and existing user privileges, but no interaction from an administrator is needed. An attacker can achieve full system compromise and persistence.

Affected products

  • Microsoft Windows Spaceport.sys <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats