{"id":"CVE-2026-15419","title":"CP210x Driver Memory Corruption results in Arbitrary Code Execution","summary":"In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.","severity":"high","cvss":7,"cvssVector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cvssSource":"cna","cwe":["CWE-121"],"vendor":"Silicon Labs","product":"silabser.sys driver","affected":["silabser.sys_driver <= 11.5.0"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-10T18:21:46.062761Z"},"published":"2026-09-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T18:21:53.494Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-15419","references":[{"url":"https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/069Vm0000100HA6IAM?operationContext=S1"}],"tags":["cve.org"],"epss":0.0017,"epssPercentile":0.0673,"ingestedAt":"2026-09-11T16:45:48.027Z","slug":"CVE-2026-15419","body":"## Overview\n\nIn the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.\n\n## Affected\n\n- `silabser.sys_driver <= 11.5.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}