Description
In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash.
Published: 2026-09-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Kernel Crash
Action: Update Driver
AI Analysis

Impact

the silabser.sys driver for CP210x USB devices can supply incorrect configuration values that trigger a kernel mode crash, resulting in an unresponsive operating system state. This denial of service results from a fundamental flaw: the driver does not validate input settings properly before applying them, causing a critical failure in kernel execution. The weakness is categorized as CWE‑369, which identifies insecure handling that can drive the kernel into an invalid state.

Affected Systems

The affected product is the silabser.sys kernel driver distributed by Silicon Labs for CP210x USB-to-UART interface chips. The documented CVE targets Windows 8 and presumably newer Windows releases that still load this driver. No specific version numbers are listed beyond the operating system requirement; however, all builds of silabser.sys that ship with CP210x devices may be impacted.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity for local denial of service. The EPSS score is unavailable, and the vulnerability is not in the CISA KEV list, suggesting low or uncertain exploitation probability at this time. The primary attack vector is local: a non‑privileged user must possess the CP210x hardware and have the ability to change driver settings, which is normally exposed through device manager or configuration utilities. Because the flaw is limited to the local machine and does not rely on remote input, the damage is restricted to a single system. Nonetheless, any compromise of local management privileges could allow the attacker to repeatedly crash the operating system, disrupting availability.

Generated by OpenCVE AI on September 11, 2026 at 00:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check with Silicon Labs for any available updates to silabser.sys that address input validation issues.
  • If the CP210x device is not required, consider uninstalling the silabser.sys driver so that the vulnerable code never runs.
  • Restrict access to the driver configuration tools; only administrative users should be allowed to modify CP210x settings, preventing unprivileged users from supplying malicious configurations.

Generated by OpenCVE AI on September 11, 2026 at 00:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash.
Title CP210x Denial of Service
Weaknesses CWE-369
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-09-10T18:21:00.773Z

Reserved: 2026-07-10T14:57:33.010Z

Link: CVE-2026-15417

cve-icon Vulnrichment

Updated: 2026-09-10T18:20:55.428Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T18:17:55.313

Modified: 2026-09-10T19:54:25.810

Link: CVE-2026-15417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:15:17Z

Weaknesses