Junglewise Threat Intelligence

CVE-2026-71350: Microsoft Windows Spaceport.sys heap buffer overflow

CVE-2026-71350 · Severity: medium · CVSS 6.8 · Published 2026-09-08

Executive brief

A heap-based buffer overflow vulnerability exists in Windows Spaceport.sys, a system driver responsible for handling memory management operations. An attacker with physical access to a machine can exploit this flaw to execute arbitrary code with kernel privileges, potentially compromising system integrity and security controls.

Technical details

A heap-based buffer overflow exists in Windows Spaceport.sys that allows arbitrary code execution. The vulnerability is triggered during memory handling operations and can be exploited by an attacker with physical access to the system. The attack does not require prior authentication or elevated user privileges, though it is limited to physical attack vectors. A patch is available from Microsoft.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats