CVE-2026-23764
Last modified
CVE-2026-23764 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers (vbvoicemeetervaio64*.sys, vbmatrixvaio64*.sys, vbaudio_vmauxvaio*.sys, vbaudio_vmvaio*.sys, and vbaudio_vmvaio3*.sys). The drivers allocate non-paged pool and map it into user space, where a length value associated with the allocation is exposed and can be modified by an unprivileged local attacker. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers (vbvoicemeetervaio64*.sys, vbmatrixvaio64*.sys, vbaudio_vmauxvaio*.sys, vbaudio_vmvaio*.sys, and vbaudio_vmvaio3*.sys). The drivers allocate non-paged pool and map it into user space, where a length value associated with the allocation is exposed and can be modified by an unprivileged local attacker. On subsequent IOCTL handling, the corrupted length is used directly as the IoAllocateMdl length argument without adequate integrity checks before building and mapping the MDL, which can cause a kernel crash (BSoD), typically PAGE_FAULT_IN_NONPAGED_AREA. This flaw allows a local user to trigger a denial-of-service on affected Windows systems.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-23764?
How severe is CVE-2026-23764?
How do I fix CVE-2026-23764?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23759Perle IOLAN STS/SCS terminal server models with firmware ver…8.6
- CVE-2026-2376A flaw was found in mirror-registry where an authenticated u…5.4
- CVE-2026-23760SmarterTools SmarterMail versions prior to build 9511 contai…9.8
- CVE-2026-23761VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Po…6.9
- CVE-2026-23762VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Po…6.9
- CVE-2026-23763VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2…8.5
- CVE-2026-23765Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-23766Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2026-23767ESC/POS, a printer control language designed by Seiko Epson …9.8
- CVE-2026-23768lucy-xss-filter before commit 7c1de6d allows an attacker to …6.1
- CVE-2026-23769lucy-xss-filter before commit e5826c0 allows an attacker to …6.1
- CVE-2026-2377A flaw was found in Red Hat Quay and mirror registry for Red…6.5
Are you affected by CVE-2026-23764?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
