Skip to finding
important · Physical — Windows

Attacker-controlled storage can reach Windows kernel code execution through Spaceport.sys.

Affects

Microsoft Windows 10, Windows 11, and Windows Server, desktop and server operating systems.

Physical access is sufficient to present input that reaches a heap-based buffer overflow in the storage driver; no account or user interaction is recorded.

Detail and 2 sources

We do not know the storage transport, malformed structure, or whether the path works at the lock screen or before sign-in.

The affected population includes end-of-life Windows hardware.

Chain to watch
Present attacker-controlled storage to an affected Windows machine→↓Trigger the Spaceport.sys heap overflow→↓Reach kernel-context code execution→↓The storage transport, malformed input and lock-screen or pre-sign-in reach are unknown.
Unverified chainDiff Spaceport.sys across the September fixed-build boundaries, identify the changed parser, and exercise it with representative attached storage.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 13, 2026