在 CP210x 设备的 silabser.sys 驱动程序中,版本 11.5.0 及更早版本存在一个漏洞:本地非特权用户可利用恶意设备通过构造格式异常的报文,泄露最多 145 字节的未初始化内核池内存。该漏洞影响 Windows 10 及更早版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Silicon Labs | silabser.sys driver | 0 ~ 11.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15419 | 7.0 HIGH | CP210x Driver Memory Corruption results in Arbitrary Code Execution |
| CVE-2026-15417 | 6.9 MEDIUM | CP210x Denial of Service |
No comments yet