Executive brief
The silabser.sys Windows driver for CP210x USB-to-serial devices contains a vulnerability that allows any local user to crash the Windows kernel by configuring incorrect driver settings. This denial-of-service condition could cause unexpected system downtime or be used as a foothold for privilege escalation attacks in multi-user environments.
Technical details
This is a denial-of-service vulnerability in the silabser.sys kernel driver for CP210x serial devices under Windows 8. An unprivileged local user can trigger a kernel crash by supplying malformed or out-of-range parameters to the driver. No special privileges or code execution capability is required—only local access and the ability to interact with the driver interface. The vulnerability allows an attacker to cause a kernel panic, resulting in system unavailability. The issue has been reported to Silicon Labs and patches may be available through driver updates.
Affected products
- Silicon Labs CP210x silabser.sys driver Windows 8
Timeline
- 2026-09-10: disclosed