Junglewise Threat Intelligence

CVE-2026-72942: Microsoft Windows Spaceport.sys out-of-bounds read

CVE-2026-72942 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Spaceport.sys is a Windows system driver responsible for hardware component initialization. An out-of-bounds read vulnerability allows an attacker to disclose sensitive information from system memory over a network without requiring authentication, potentially exposing configuration data or other protected details.

Technical details

The vulnerability is an out-of-bounds read in the Windows Spaceport.sys driver that allows information disclosure. An attacker can trigger the out-of-bounds read via network-based attack without requiring authentication. Successful exploitation enables the attacker to read sensitive data from kernel memory, potentially leaking system information, security tokens, or other protected data. A patch has been released by Microsoft via their security update process.

Affected products

  • Microsoft Windows Spaceport.sys

Timeline

  • 2026-09-08: disclosed

References

Related threats