Executive brief
Spaceport.sys is a Windows system driver responsible for hardware component initialization. An out-of-bounds read vulnerability allows an attacker to disclose sensitive information from system memory over a network without requiring authentication, potentially exposing configuration data or other protected details.
Technical details
The vulnerability is an out-of-bounds read in the Windows Spaceport.sys driver that allows information disclosure. An attacker can trigger the out-of-bounds read via network-based attack without requiring authentication. Successful exploitation enables the attacker to read sensitive data from kernel memory, potentially leaking system information, security tokens, or other protected data. A patch has been released by Microsoft via their security update process.
Affected products
- Microsoft Windows Spaceport.sys
Timeline
- 2026-09-08: disclosed