CyberRota Analysis
AI-GeneratedThe silabser.sys driver for CP210x devices versions 11.5.0 and earlier is vulnerable to arbitrary code execution due to improper handling of malformed packets by local unprivileged users with malicious devices, leading to potential kernel pool memory corruption. This vulnerability allows attackers to escalate privileges on affected systems, posing a significant risk to system integrity and security. Organizations utilizing CP210x devices should prioritize patching or mitigating this vulnerability to protect against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.