ZeroHour

CVE-2026-69538

mass

Out-of-bounds read in Windows Spaceport.sys driver enables local code execution

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-69538 is an out-of-bounds read vulnerability (CWE-125) in Spaceport.sys, the Windows Storage Space Port kernel driver that supports Windows storage features such as Storage Spaces. According to Microsoft, an authorized local user can trigger the flaw by exercising the affected code path in the driver, with low privileges and no user interaction required. Successful exploitation allows the attacker to execute code locally, with high impact rated across confidentiality, integrity, and availability (CVSS 3.1: 7.8); given the component is a kernel driver, this likely means code execution with elevated, potentially kernel-level, context. Any Windows system running the affected Spaceport.sys component is potentially exposed, though the available data does not enumerate specific affected Windows version ranges. There is currently no known exploitation: no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days (16th percentile).

What to do: Monitor Microsoft's advisory to identify the affected Windows versions and apply the vendor's Windows security update as soon as it is released, since no workaround is documented in the available data. Until patched, prioritize hosts where untrusted or low-privileged users can run code (shared workstations, multi-user servers, VDI), as exploitation requires local access. No in-the-wild exploitation or public PoC is currently known, so standard patch-cadence handling is appropriate.

Affected
Microsoft Windows (Spaceport.sys storage driver)
Estimated exposure
masshundreds of millions of Windows systems (Spaceport.sys ships as a standard Windows component; the Windows installed base is on the order of a billion devices) — Spaceport.sys is a standard inbox Windows driver, so the potentially affected population scales with the Windows installed base; because Microsoft's advisory in this data does not list affected versions, the true count could be lower,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.

Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.