ZeroHour

CVE-2026-15419

mass

Kernel Pool Memory Corruption in Silicon Labs CP210x Windows Driver (silabser.sys)

CVSS 4.0
7.0 high
EPSS
Published
()
Modified
AI analysis

A buffer overflow classified as CWE-121 in silabser.sys, the Windows kernel driver for Silicon Labs CP210x USB-to-UART bridge devices, version 11.5.0 and earlier, allows kernel pool memory to be corrupted via malformed packets sent by the device. An unprivileged local user who connects — or already controls — a malicious USB device that enumerates as a CP210x device can trigger the corruption, yielding arbitrary code execution with escalated (kernel-level) privileges on the host. CVSS 4.0 rates the attack vector as physical with no privileges required and High impact on confidentiality, integrity, and availability. Any Windows machine with the Silicon Labs CP210x driver (v11.5.0 or earlier) installed is affected, with practical risk limited to hosts where an untrusted user or device can reach a USB port. No exploitation in the wild, public proof-of-concept, or CISA KEV listing is currently known.

What to do: Upgrade silabser.sys on all Windows hosts that use CP210x devices to the first fixed release newer than v11.5.0, checking Silicon Labs' security advisory for the exact patched build. Until patched, restrict which USB devices can be connected to sensitive hosts, since exploitation requires physical access with a malicious device that enumerates as a CP210x. Verify the installed driver version via Device Manager or the version properties of the silabser.sys file.

Affected
Silicon Labs silabser.sys Windows kernel driver for CP210x USB-to-UART bridge devicesv11.5.0 and earlier
Estimated exposure
massplausibly millions of Windows hosts with the CP210x driver installed (estimated) — CP210x USB-to-UART bridges are among the most widely deployed chips of their kind, bundled with popular developer and hobbyist boards, embedded and industrial products, and the driver commonly auto-installs on Windows hosts when such a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.

Weakness
CWE-121
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.