Impact
The silabser allows a local unprivileged user to send malformed packets to a malicious or compromised CP210x device, causing the driver to leak up to 145 bytes of uninitialized kernel pool memory. This disclosure of kernel data is a Local Information Disclosure vulnerability and is identified as CWE‑130, improper handling of kernel memory. The amount of data exposed is small and does not allow for direct privilege escalation, but could aid an attacker in refining further exploit attempts.
Affected Systems
The flaw exists in the siliconlabs silabser.sys driver for CP210x devices when the driver version is 11.5.0 or older. Any Windows 10 or earlier operating system that has this driver installed is affected. The kernel memory leakage can occur only on systems running the affected driver with a CP210x device connected.
Risk and Exploitability
The attack vector requires a local unprivileged user with a malicious CP210x device connected to the target. The exploit does not provide elevated privileges or system compromise beyond the memory leak. The CVSS base score of 2.4 reflects low severity, and because the EPSS score is unavailable and the vulnerability is not listed in the KEV catalog, the considered low.
OpenCVE Enrichment