Executive brief
Spaceport.sys is a Windows kernel component responsible for GPU memory management. A numeric truncation error in this component allows an authorized local attacker to escape privilege boundaries and gain elevated system access, potentially compromising the entire machine.
Technical details
A numeric truncation vulnerability exists in Windows Spaceport.sys, a kernel-mode driver handling GPU/graphics memory operations. The flaw allows an authenticated local attacker to bypass privilege validation through integer truncation, resulting in arbitrary kernel-level code execution. Exploitation requires local access and existing user privileges, but no interaction from an administrator is needed. An attacker can achieve full system compromise and persistence.
Affected products
- Microsoft Windows Spaceport.sys <UNKNOWN>
Timeline
- 2026-09-08: disclosed