Executive brief
A flaw in Windows Spaceport.sys, a core Windows kernel driver, allows an attacker with local access to read memory beyond intended boundaries and elevate their privileges. This could enable an authorized user to gain administrator-level access to a system, compromising its security and allowing full control over data and operations.
Technical details
An out-of-bounds read vulnerability exists in Windows Spaceport.sys that can be exploited by an authenticated local attacker to escalate privileges. The vulnerability stems from improper bounds checking in the driver's memory access operations, allowing read access to kernel memory outside the intended buffer. An attacker with local code execution can trigger this flaw to leak sensitive kernel information and escalate from user to SYSTEM-level privileges. A patch from Microsoft is available through standard Windows security updates.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed