Junglewise Threat Intelligence

CVE-2026-69643: Microsoft Windows Spaceport.sys heap-based buffer overflow

CVE-2026-69643 · Severity: high · CVSS 8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Spaceport.sys is a kernel-mode driver used for system operations. A heap-based buffer overflow in this component allows an authorized attacker to elevate their privileges and potentially compromise system integrity and confidentiality across a network.

Technical details

The vulnerability is a heap-based buffer overflow in Windows Spaceport.sys, a kernel-mode driver. An authorized attacker can trigger the overflow through network-reachable mechanisms to elevate privileges. The attack requires prior authentication or authorization, but can result in kernel-level code execution and privilege escalation, potentially compromising the entire system. A security update has been published by Microsoft.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats