ZeroHour

CVE-2026-69535

mass

Local Privilege Elevation via Numeric Truncation in Windows Spaceport.sys

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-69535 is a numeric truncation error (CWE-197) in spaceport.sys, the Windows Storage Spaces driver, that Microsoft rates High severity (CVSS 3.1: 7.8) for local privilege elevation. An attacker who already holds valid low-privileged access on a local Windows host can trigger the truncation error, causing kernel-mode memory corruption consistent with a heap-based buffer overflow (CWE-122). Successful exploitation yields full elevation of privilege, with high impact on confidentiality, integrity, and availability (SYSTEM-level control of the host). All Windows editions that ship the affected spaceport.sys driver are potentially affected; the available data does not specify exact Windows version ranges, so defenders should consult Microsoft's advisory for the definitive build list. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% (16th percentile) probability of exploitation within 30 days, indicating no known exploitation at this time.

What to do: Track Microsoft's advisory (MSRC/CNA [email protected]) for the exact affected builds and apply the corresponding Windows security update as soon as it is released, then verify the patched spaceport.sys file version on critical hosts. Until patched, restrict local logon and RDP access to trusted users and remove standard-user local access on sensitive servers to shrink the attack surface. Given the lack of public PoC and low EPSS (0.2%), patch end-user devices within normal cycles and prioritize multi-user or remotely-accessed Windows systems first.

Affected
Microsoft Windows (spaceport.sys Storage Spaces kernel driver)
Estimated exposure
massorder of 10^8-10^9 Windows devices (essentially the global Windows installed base runs spaceport.sys; exact affected subset unknown pending Microsoft's build… — spaceport.sys ships with Windows client and server editions whose combined installed base exceeds one billion devices, so any host on an affected build is exposed, though the flaw requires an attacker to already have local low-privileged…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122, CWE-197
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.