ZeroHour

CVE-2026-70569

mass

Out-of-bounds Read in Microsoft Windows Spaceport.sys Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-70569 is an out-of-bounds read (CWE-125) in Spaceport.sys, the in-box Windows kernel driver that implements the Storage Spaces storage virtualization feature. An attacker who already has a foothold on a system via a local, low-privileged account can trigger the flaw through Windows storage functionality, causing the kernel to read memory outside the intended buffer. Successful exploitation yields elevated privileges on the local machine (CVSS 3.1 base score 7.8, high impact on confidentiality, integrity, and availability), though it does not by itself enable remote compromise. Any Windows installation on which untrusted users can run code is potentially affected; the source data does not specify affected Windows edition or build ranges. There is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.3% probability of exploitation within 30 days, indicating exploitation is not currently observed.

What to do: Install Microsoft's security update addressing CVE-2026-70569 as soon as it is available through Windows Update, and inventory systems (especially multi-user servers and endpoints with untrusted local accounts) until patches are applied. As interim mitigation, limit execution of untrusted code by local low-privileged users, since exploitation requires an existing local foothold. Given no public PoC and low EPSS (0.3%), prioritize alongside other Windows updates rather than as an emergency.

Affected
Microsoft Windows (Spaceport.sys kernel driver)
Estimated exposure
mass≈1 billion+ Windows installations (in-box kernel driver present on essentially all Windows client and server systems) — Spaceport.sys ships in the box with Windows, and Windows' installed base is on the order of a billion active devices, so exposure scales with the entire Windows population even though only local users can trigger the flaw.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.