CVE-2026-15418: CP210x Memory Leakage
Published Sep 10, 2026
·Updated
In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier.
Affected Software
1 affected component
Silicon Labs silabser.sys (CP210x driver)<=11.5.0
Event History
Sep 10, 2026
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to exploitation?
Windows 10 and earlier systems using the Silicon Labs CP210x silabser.sys driver version 11.5.0 or earlier are affected. Exploitation requires a local unprivileged user and a malicious CP210x device.
2
What can an attacker obtain through this issue?
Malformed packets from the malicious device can cause disclosure of up to 145 bytes of uninitialized kernel pool memory.