Impact
the silabser.sys driver for CP210x USB devices can supply incorrect configuration values that trigger a kernel mode crash, resulting in an unresponsive operating system state. This denial of service results from a fundamental flaw: the driver does not validate input settings properly before applying them, causing a critical failure in kernel execution. The weakness is categorized as CWE‑369, which identifies insecure handling that can drive the kernel into an invalid state.
Affected Systems
The affected product is the silabser.sys kernel driver distributed by Silicon Labs for CP210x USB-to-UART interface chips. The documented CVE targets Windows 8 and presumably newer Windows releases that still load this driver. No specific version numbers are listed beyond the operating system requirement; however, all builds of silabser.sys that ship with CP210x devices may be impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity for local denial of service. The EPSS score is unavailable, and the vulnerability is not in the CISA KEV list, suggesting low or uncertain exploitation probability at this time. The primary attack vector is local: a non‑privileged user must possess the CP210x hardware and have the ability to change driver settings, which is normally exposed through device manager or configuration utilities. Because the flaw is limited to the local machine and does not rely on remote input, the damage is restricted to a single system. Nonetheless, any compromise of local management privileges could allow the attacker to repeatedly crash the operating system, disrupting availability.
OpenCVE Enrichment