ZeroHour

CVE-2026-72952

mass

Out-of-bounds read in Windows Spaceport.sys driver enables local code execution

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-72952 is an out-of-bounds read (CWE-125) in Spaceport.sys, the inbox Windows driver that supports the Storage Spaces feature, rated 7.0 (High) on CVSS 3.1. It is triggered by an authorized, low-privileged local user, and the high attack-complexity score indicates specific conditions must be met for the flaw to be exploitable. Per Microsoft's description, successful exploitation allows the attacker to execute code locally on the affected machine. Any Windows edition that ships this driver is potentially in scope, but the source data does not specify affected version ranges, so defenders should confirm applicability against Microsoft's advisory. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Check Microsoft's advisory for CVE-2026-72952 to identify affected builds and apply the vendor patch when available, prioritizing multi-user systems such as RDS/VDI hosts and shared workstations where untrusted local logon is permitted. As an interim measure, restrict local logon rights to trusted users, since exploitation requires an authorized local account.

Affected
Microsoft Windows (Spaceport.sys, Storage Spaces driver)
Estimated exposure
masson the order of 1+ billion Windows devices ship the affected driver — Spaceport.sys is a standard inbox component of modern Windows client and server editions, and Microsoft has reported more than 1.4 billion active Windows 10/11 devices, so the potential install base exceeds one billion systems.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.

Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.