CVE-2024-9495

HIGH

CP210x VCP Windows - Privilege Escalation

Title source: llm

Description

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the CP210x VCP Windows installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

Scores

CVSS v3 8.6
EPSS 0.0008
EPSS Percentile 22.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Classification

CWE
CWE-427
Status draft

Timeline

Published Jan 24, 2025
Tracked Since Feb 18, 2026