CVE-2026-69538
massOut-of-bounds read in Windows Spaceport.sys driver enables local code execution
CVE-2026-69538 is an out-of-bounds read vulnerability (CWE-125) in Spaceport.sys, the Windows Storage Space Port kernel driver that supports Windows storage features such as Storage Spaces. According to Microsoft, an authorized local user can trigger the flaw by exercising the affected code path in the driver, with low privileges and no user interaction required. Successful exploitation allows the attacker to execute code locally, with high impact rated across confidentiality, integrity, and availability (CVSS 3.1: 7.8); given the component is a kernel driver, this likely means code execution with elevated, potentially kernel-level, context. Any Windows system running the affected Spaceport.sys component is potentially exposed, though the available data does not enumerate specific affected Windows version ranges. There is currently no known exploitation: no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days (16th percentile).
What to do: Monitor Microsoft's advisory to identify the affected Windows versions and apply the vendor's Windows security update as soon as it is released, since no workaround is documented in the available data. Until patched, prioritize hosts where untrusted or low-privileged users can run code (shared workstations, multi-user servers, VDI), as exploitation requires local access. No in-the-wild exploitation or public PoC is currently known, so standard patch-cadence handling is appropriate.
| Microsoft Windows (Spaceport.sys storage driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.