ZeroHour

CVE-2026-69512

mass

Heap Buffer Overflow in Windows Spaceport.sys Enables Network Privilege Escalation

CVSS 3.1
8.0 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-69512 is a heap-based buffer overflow in Spaceport.sys, the Windows Storage Spaces port driver, with an underlying numeric type issue (CWE-197) that can lead to an undersized allocation and out-of-bounds writes (CWE-122). It is triggered over a network by a low-privileged, authorized user, with user interaction required before the overflow occurs. A successful exploit grants kernel-level privilege escalation, giving the attacker high impact on confidentiality, integrity, and availability of the host. Any Windows system running the Spaceport.sys driver is potentially affected, though the data does not specify which Windows releases or version ranges are vulnerable. Exploitation status: no public proof-of-concept, not listed in CISA's KEV, and EPSS puts 30-day exploitation probability at only 0.8%, so no active exploitation is known.

What to do: Apply Microsoft's security update addressing CVE-2026-69512 as soon as it is available, checking Microsoft's advisory for the exact affected Windows releases since version ranges are not provided here. In the meantime, inventory hosts using Storage Spaces (presence of Spaceport.sys) and prioritize patching internet-reachable or multi-user Windows systems. Restrict low-privileged interactive network access to sensitive Windows hosts to reduce the user-assisted attack surface until patched.

Affected
Microsoft Windows (Spaceport.sys Storage Spaces port driver)
Estimated exposure
masspotentially hundreds of millions of Windows devices (Windows installed base exceeds 1 billion) — Spaceport.sys ships with modern Windows client and server releases and the Windows installed base is on the order of 1+ billion devices, so even the subset of systems using or loading the Storage Spaces driver plausibly reaches hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-122, CWE-197
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.