CVE-2024-9495 is a high-severity DLL hijacking vulnerability in the CP210x VCP Windows installer, allowing privilege escalation and arbitrary code execution due to an uncontrolled search path. With a CVSS score of 8.6, an attacker could exploit this locally with low complexity, requiring user interaction, to gain full control over the system. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Silabs.Com | CP210x VCP Windows | >= 0, <= 6.7CNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.