Denial-of-Service Vulnerability in VB-Audio Voicemeeter and Matrix Products
CVE-2026-23762
Key Information:
- Vendor
Vb-audio Software
- Vendor
- CVE Published:
- 22 January 2026
Badges
What is CVE-2026-23762?
VB-Audio's Voicemeeter and Matrix products have a vulnerability in their virtual audio drivers that can lead to denial-of-service attacks. Specifically, improper exception handling in the driver allows a local unprivileged user to map non-paged pool memory into user space, potentially resulting in a system crash. Upon failure of the memory mapping due to exhausted virtual address space, an unhandled exception is raised, leading to a Blue Screen of Death (BSoD) with SYSTEM_SERVICE_EXCEPTION and STATUS_NO_MEMORY errors. This issue affects various versions of Voicemeeter, Voicemeeter Banana, Voicemeeter Potato, Matrix, and Matrix Coconut products.
Affected Version(s)
Matrix Coconut Windows 0 <= 2.0.2.2
Matrix Windows 0 <= 1.0.2.2
Voicemeeter (Standard) Windows 0 <= 1.1.1.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
