CVE-2026-50298
Analyzed Analyzed - Analysis Complete

Integer Overflow in Windows Spaceport.sys Leads to Privilege Escalation

Vulnerability report for CVE-2026-50298, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50298 is an integer overflow or wraparound vulnerability in the Windows Spaceport.sys driver. This flaw allows an unauthorized attacker to elevate their privileges on a targeted system.

The vulnerability requires physical access to the system to exploit, meaning the attacker must have direct hardware-level interaction with the affected device.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-50298 on a network or system. This vulnerability involves an integer overflow or wraparound in Windows Spaceport.sys, which requires physical access to exploit. Detection may involve checking system logs, driver versions, or using Microsoft-provided tools for vulnerability assessment, but no explicit commands or tools are mentioned in the available resources.

To detect this vulnerability, you may need to verify the installed version of the Windows Spaceport.sys driver or apply Microsoft's official updates. Refer to Microsoft's update guide for specific detection guidance.

Impact Analysis

If exploited, this vulnerability can have severe consequences, including:

  • Unauthorized privilege escalation, allowing an attacker to gain higher-level access to the system.
  • Potential compromise of sensitive data, system integrity, or availability, as the attacker could execute arbitrary code with elevated permissions.

However, exploitation requires physical access, which limits the attack surface compared to remote vulnerabilities.

Compliance Impact

This vulnerability may impact compliance with standards and regulations in the following ways:

  • GDPR: If the affected system processes personal data of EU citizens, a successful exploit could lead to unauthorized access or disclosure, violating GDPR requirements for data protection and breach notification.
  • HIPAA: For healthcare organizations, exploitation could result in unauthorized access to protected health information (PHI), violating HIPAA's security and privacy rules.
  • Other standards (e.g., ISO 27001, NIST): The vulnerability may indicate a failure to implement adequate access controls or vulnerability management, potentially leading to non-compliance with security best practices.

Organizations should assess their exposure and apply patches or mitigations to maintain compliance.

Mitigation Strategies

Based on the provided context, the following steps can be taken to mitigate CVE-2026-50298:

  • Apply the official security update provided by Microsoft as soon as possible. The update is referenced in the Microsoft Security Response Center (MSRC) update guide for this CVE.
  • Restrict physical access to systems running the vulnerable Windows Spaceport.sys driver, as the vulnerability requires physical access to exploit.
  • Monitor Microsoft's official communications for additional mitigation guidance or workarounds if an update is not immediately available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50298. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart