CVE-2026-15418

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier.

Scoring

Severity
LOW
CVSS base score
2.4
CVSS vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWE
CWE-130
Published
2026-09-10
Last modified
2026-09-10

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs