CVE-2026-15419: CP210x Driver Memory Corruption results in Arbitrary Code Execution
Published Sep 10, 2026
·Updated
In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.
Affected Software
1 affected component
Silicon Labs CP210x Driver (silabser.sys)<=11.5.0
Event History
Sep 10, 2026
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to exploitation?
Systems using the Silicon Labs CP210x silabser.sys driver version 11.5.0 or earlier are exposed if a local unprivileged user can use a malicious CP210x device.
2
What does an attacker need to exploit this issue?
The attacker needs local, unprivileged access and a malicious device capable of sending malformed packets to the driver. Successful exploitation corrupts kernel pool memory and can result in arbitrary code execution with escalated privileges.