Junglewise Threat Intelligence

CVE-2026-69538: Microsoft Windows Spaceport.sys out-of-bounds read

CVE-2026-69538 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Spaceport.sys is a system driver responsible for display and graphics operations on Windows systems. An authorized local attacker can exploit an out-of-bounds read vulnerability to execute arbitrary code with elevated privileges, potentially compromising the entire system.

Technical details

The vulnerability is an out-of-bounds read flaw in the Windows Spaceport.sys driver. An authenticated local attacker can trigger the vulnerability through a specially crafted request, leading to memory disclosure and subsequent code execution. The attack requires local access and existing authentication on the target system. Successful exploitation allows arbitrary code execution in kernel context, providing full system compromise. Microsoft has released patches to address this vulnerability.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats