Denial-of-Service Vulnerability in VB-Audio Voicemeeter and Matrix Products
CVE-2026-23764
Key Information:
- Vendor
Vb-audio Software
- Vendor
- CVE Published:
- 22 January 2026
Badges
What is CVE-2026-23764?
VB-Audio's Voicemeeter and Matrix products are affected by a vulnerability in their virtual audio drivers. This flaw allows a local, unprivileged attacker to exploit a memory allocation issue, exposing a length value associated with the allocation. By corrupting this length, the attacker can trigger a denial-of-service condition, leading to system instability and potentially causing a Blue Screen of Death (BSoD) in affected Windows systems. The issue is related to how IOCTL requests handle corrupted memory lengths, resulting in crashes that disrupt system operations.
Affected Version(s)
Matrix Coconut Windows 0 <= 2.0.2.2
Matrix Windows 0 <= 1.0.2.2
Voicemeeter (Standard) Windows 0 <= 1.1.1.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
