CVE-2024-9498

HIGH

USBXpress SDK - Privilege Escalation

Title source: llm
STIX 2.1

Description

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress SDK installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

References (1)

Core 1
Core References
Various Sources vendor-advisory permissions-required
https://community.silabs.com/068Vm00000JUQwd

Scores

CVSS v3 8.6
EPSS 0.0022
EPSS Percentile 12.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
silabs.com/USBXpress SDK < 6.7.3
Published Jan 24, 2025
Tracked Since Feb 18, 2026