ZeroHour

CVE-2026-69691

mass

Heap Buffer Overflow in Windows Spaceport.sys Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69691 is a heap-based buffer overflow (CWE-122) in Spaceport.sys, the Windows kernel driver that underpins Storage Spaces. It is triggered locally by an authorized attacker who already holds limited privileges on the target system, rather than through a network-facing attack path. Successful exploitation allows the attacker to elevate their privileges within the Windows kernel, yielding high impact on confidentiality, integrity, and availability — effectively full control of the host. Any Windows system running an affected build that includes Spaceport.sys is potentially affected, though the data provided does not specify version ranges. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for this CVE via Windows Update as soon as it is released, prioritizing multi-user systems such as RDS/session hosts, shared workstations, and administrative jump boxes where local privilege escalation has the greatest downstream impact. Because this is a local attack requiring an authorized account, focus on controlling who has local sign-in rights and watching for suspicious local account activity; no network-level mitigation or workaround is indicated in the available data. Check the Microsoft advisory for the definitive list of affected builds before patching, since version ranges were not provided in this dataset.

Affected
Microsoft Windows (Spaceport.sys / Storage Spaces driver)
Estimated exposure
mass≈1 billion+ Windows installations (driver ships with Windows) — Spaceport.sys is a standard component of the Windows kernel, and Windows runs on well over a billion active devices worldwide, so the theoretical population of systems carrying this driver is enormous even though only a subset may use…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.