CVE-2026-69691
massHeap Buffer Overflow in Windows Spaceport.sys Enables Local Privilege Escalation
CVE-2026-69691 is a heap-based buffer overflow (CWE-122) in Spaceport.sys, the Windows kernel driver that underpins Storage Spaces. It is triggered locally by an authorized attacker who already holds limited privileges on the target system, rather than through a network-facing attack path. Successful exploitation allows the attacker to elevate their privileges within the Windows kernel, yielding high impact on confidentiality, integrity, and availability — effectively full control of the host. Any Windows system running an affected build that includes Spaceport.sys is potentially affected, though the data provided does not specify version ranges. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.3% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for this CVE via Windows Update as soon as it is released, prioritizing multi-user systems such as RDS/session hosts, shared workstations, and administrative jump boxes where local privilege escalation has the greatest downstream impact. Because this is a local attack requiring an authorized account, focus on controlling who has local sign-in rights and watching for suspicious local account activity; no network-level mitigation or workaround is indicated in the available data. Check the Microsoft advisory for the definitive list of affected builds before patching, since version ranges were not provided in this dataset.
| Microsoft Windows (Spaceport.sys / Storage Spaces driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.