Impact
A local unprivileged user who has physical access to a CP210x USB device can send specially crafted packets to the Silicon Labs silabser.sys driver. The driver processes these packets without adequate bounds checking, corrupting kernel pool memory and allowing the attacker to execute arbitrary code with escalated privileges.
Affected Systems
Silicon Labs silabser.sys driver for CP210x devices, versions 11.5.0 and earlier.
Risk and Exploitability
The CVSS score of 7 indicates moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Attackers need local access to the device and the ability to generate malformed packets; no network component is required. If exploited, the attacker would gain kernel‑level code execution, compromising confidentiality, integrity, and availability of the affected system.
OpenCVE Enrichment