CVE-2026-69512
massHeap Buffer Overflow in Windows Spaceport.sys Enables Network Privilege Escalation
CVE-2026-69512 is a heap-based buffer overflow in Spaceport.sys, the Windows Storage Spaces port driver, with an underlying numeric type issue (CWE-197) that can lead to an undersized allocation and out-of-bounds writes (CWE-122). It is triggered over a network by a low-privileged, authorized user, with user interaction required before the overflow occurs. A successful exploit grants kernel-level privilege escalation, giving the attacker high impact on confidentiality, integrity, and availability of the host. Any Windows system running the Spaceport.sys driver is potentially affected, though the data does not specify which Windows releases or version ranges are vulnerable. Exploitation status: no public proof-of-concept, not listed in CISA's KEV, and EPSS puts 30-day exploitation probability at only 0.8%, so no active exploitation is known.
What to do: Apply Microsoft's security update addressing CVE-2026-69512 as soon as it is available, checking Microsoft's advisory for the exact affected Windows releases since version ranges are not provided here. In the meantime, inventory hosts using Storage Spaces (presence of Spaceport.sys) and prioritize patching internet-reachable or multi-user Windows systems. Restrict low-privileged interactive network access to sensitive Windows hosts to reduce the user-assisted attack surface until patched.
| Microsoft Windows (Spaceport.sys Storage Spaces port driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-122, CWE-197
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.