CVE-2026-71345
massOut-of-Bounds Write in Microsoft Windows Spaceport.sys Enables Local Code Execution
CVE-2026-71345 is an out-of-bounds write (CWE-787) in Spaceport.sys, the inbox Windows Storage Spaces driver, which Microsoft rates High (CVSS 3.1: 7.8) with a local attack vector and low required privileges. An authorized, locally authenticated user can trigger the memory-corruption flaw to execute code on the affected system, with high confidentiality, integrity, and availability impact consistent with kernel-level code execution. All Windows editions that ship the Spaceport.sys driver are potentially affected, although the provided data does not specify exact version ranges, so defenders should consult Microsoft's advisory for the definitive affected-product list. Exploitation activity is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Install Microsoft's security update for CVE-2026-71345 as soon as it is available, prioritizing multi-user Windows hosts and systems where untrusted or low-privileged local accounts exist. Until patching, restrict local logon rights to trusted users and watch for unusual local process or driver activity. Because the flaw requires local access, internet-facing exposure alone does not raise immediate risk, but treat it as a standard local privilege-escalation patch priority.
| Microsoft Windows (Spaceport.sys, inbox Storage Spaces driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.