Denial-of-Service Vulnerability in VB-Audio Voicemeeter and Matrix Drivers
CVE-2026-23761
Key Information:
- Vendor
Vb-audio Software
- Vendor
- CVE Published:
- 22 January 2026
Badges
What is CVE-2026-23761?
The vulnerability in VB-Audio's Voicemeeter and Matrix products arises from improper initialization of FILE_OBJECT->FsContext in their virtual audio drivers. An unprivileged local user can exploit this flaw by opening a handle with specific file attribute values. If the driver does not correctly manage subsequent operations, it could lead to dereferencing an invalid FsContext value, resulting in a Blue Screen of Death (BSoD) on the affected Windows systems. This can severely disrupt audio processing and cause significant denial-of-service issues.
Affected Version(s)
Matrix Coconut Windows 0 <= 2.0.2.2
Matrix Windows 0 <= 1.0.2.2
Voicemeeter (Standard) Windows 0 <= 1.1.1.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
