Executive brief
Windows Spaceport.sys contains an uninitialized resource that allows an authorized local attacker to read sensitive information from system memory. This vulnerability could expose confidential data such as encryption keys, credentials, or other sensitive details that were previously written to memory. While exploitation requires local access and prior authorization, successful exploitation could compromise the confidentiality of critical system information.
Technical details
The vulnerability is a use-of-uninitialized-resource (CWE-908) flaw in Windows Spaceport.sys, a kernel-mode driver. An authenticated local attacker can exploit this by invoking specific driver functionality that accesses uninitialized memory, allowing information disclosure. The attack vector is local and requires either administrative privileges or an authorized user account with appropriate access rights to the driver. An attacker can read uninitialized portions of kernel memory, potentially leaking sensitive data. Microsoft has released a security update to properly initialize resources before use.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed