CVE-2026-72952
massOut-of-bounds read in Windows Spaceport.sys driver enables local code execution
CVE-2026-72952 is an out-of-bounds read (CWE-125) in Spaceport.sys, the inbox Windows driver that supports the Storage Spaces feature, rated 7.0 (High) on CVSS 3.1. It is triggered by an authorized, low-privileged local user, and the high attack-complexity score indicates specific conditions must be met for the flaw to be exploitable. Per Microsoft's description, successful exploitation allows the attacker to execute code locally on the affected machine. Any Windows edition that ships this driver is potentially in scope, but the source data does not specify affected version ranges, so defenders should confirm applicability against Microsoft's advisory. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Check Microsoft's advisory for CVE-2026-72952 to identify affected builds and apply the vendor patch when available, prioritizing multi-user systems such as RDS/VDI hosts and shared workstations where untrusted local logon is permitted. As an interim measure, restrict local logon rights to trusted users, since exploitation requires an authorized local account.
| Microsoft Windows (Spaceport.sys, Storage Spaces driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.