Local Memory Leak in CP210x Driver for Windows Operating Systems
CVE-2026-15418

2.4LOW

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-15418?

The CP210x driver for devices by Silicon Labs is vulnerable due to a flaw where a local user can exploit malformed packets sent by a malicious device. This exploit could lead to the leakage of uninitialized kernel pool memory, potentially exposing sensitive information. The issue affects various versions of the driver up to v11.5.0 on Windows 10 and earlier operating systems.

Affected Version(s)

silabser.sys driver 0 <= 11.5.0

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.