Local Privilege Escalation in CP210x Driver by Silicon Labs
CVE-2026-15419

7HIGH

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-15419?

The CP210x driver for Silicon Labs devices prior to version 11.5.0 is susceptible to a local privilege escalation vulnerability. A local unprivileged user can exploit this weakness by sending specially crafted malformed packets to the silabser.sys driver. This can lead to corruption of kernel pool memory, enabling the execution of arbitrary code with escalated privileges. It is crucial for users and system administrators to ensure their CP210x driver is updated to the latest version to mitigate this security risk.

Affected Version(s)

silabser.sys driver 0 <= 11.5.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.