SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15419

HIGH · CVSS 7 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The silabser.sys driver for CP210x devices versions 11.5.0 and earlier is vulnerable to arbitrary code execution due to improper handling of malformed packets by local unprivileged users with malicious devices, leading to potential kernel pool memory corruption. This vulnerability allows attackers to escalate privileges on affected systems, posing a significant risk to system integrity and security. Organizations utilizing CP210x devices should prioritize patching or mitigating this vulnerability to protect against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15419
Severity
HIGH
CVSS
7
EPSS
0.17%

Original NVD Description

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.