Executive brief
Spaceport.sys is a Windows kernel driver component. An out-of-bounds memory read vulnerability in this driver could allow a locally authenticated attacker to read sensitive kernel memory and potentially execute arbitrary code with system privileges, compromising the entire system.
Technical details
The vulnerability is an out-of-bounds read in the Windows Spaceport.sys kernel driver. The flaw allows an authenticated local attacker with sufficient privileges to read memory beyond allocated buffer boundaries, potentially exposing sensitive kernel data or enabling code execution. Exploitation requires local access and prior authentication. If successfully exploited, an attacker could achieve arbitrary code execution at the kernel level, gaining full system control. Microsoft has released patches to address this vulnerability.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed