SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-15418

LOW · CVSS 2.4 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The silabser.sys driver for CP210x devices in Windows 10 and earlier versions is vulnerable to a local attack where an unprivileged user can exploit malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. While the severity is classified as low, organizations using these devices should prioritize patching to mitigate potential information disclosure risks. Users of affected systems should be particularly vigilant in environments where untrusted devices may be connected.

CVE
CVE-2026-15418
Severity
LOW
CVSS
2.4
EPSS
0.15%
Windows

Original NVD Description

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier.