CVE-2026-69643
massHeap-Based Buffer Overflow in Windows Spaceport.sys Allows Privilege Elevation
CVE-2026-69643 is a heap-based buffer overflow (CWE-122) in spaceport.sys, the Windows kernel driver that implements the Storage Spaces storage virtualization feature. An authorized attacker — i.e., one holding low-privilege credentials — can trigger the flaw remotely over a network, and the CVSS vector indicates some form of user interaction is required during the attack. Successful exploitation allows the attacker to elevate privileges on the target system, with high impact on confidentiality, integrity, and availability, which is characteristic of gaining kernel- or SYSTEM-level control. Any Windows system running the vulnerable Spaceport driver is potentially affected; the source data does not specify affected or patched version ranges, so defenders should consult the Microsoft advisory for the applicable editions and fixed builds. As of this analysis there are no known public proofs-of-concept, the CVE is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a ~0.8% chance of exploitation within 30 days (53rd percentile).
What to do: Apply the Microsoft security update for CVE-2026-69643 through Windows Update or your patch management platform, prioritizing multi-user servers and other network-reachable hosts where untrusted users hold low-privilege accounts. Until patched, reduce exposure by restricting interactive logon and authentication rights on Windows systems reachable over the network, since exploitation requires an authorized account plus user interaction. Check the Microsoft advisory for the exact affected and fixed build numbers for each Windows edition in your estate.
| Microsoft Windows (Spaceport.sys / Storage Spaces driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.