CVE-2026-70569
massOut-of-bounds Read in Microsoft Windows Spaceport.sys Enables Local Privilege Escalation
CVE-2026-70569 is an out-of-bounds read (CWE-125) in Spaceport.sys, the in-box Windows kernel driver that implements the Storage Spaces storage virtualization feature. An attacker who already has a foothold on a system via a local, low-privileged account can trigger the flaw through Windows storage functionality, causing the kernel to read memory outside the intended buffer. Successful exploitation yields elevated privileges on the local machine (CVSS 3.1 base score 7.8, high impact on confidentiality, integrity, and availability), though it does not by itself enable remote compromise. Any Windows installation on which untrusted users can run code is potentially affected; the source data does not specify affected Windows edition or build ranges. There is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.3% probability of exploitation within 30 days, indicating exploitation is not currently observed.
What to do: Install Microsoft's security update addressing CVE-2026-70569 as soon as it is available through Windows Update, and inventory systems (especially multi-user servers and endpoints with untrusted local accounts) until patches are applied. As interim mitigation, limit execution of untrusted code by local low-privileged users, since exploitation requires an existing local foothold. Given no public PoC and low EPSS (0.3%), prioritize alongside other Windows updates rather than as an emergency.
| Microsoft Windows (Spaceport.sys kernel driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.