CVE Database
/

CVE-2026-23762

Back to search

CVE-2026-23762

Published: Jan 22, 2026

Modified: May 14, 2026

PUBLISHED

Description

VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers (vbvoicemeetervaio64*.sys, vbmatrixvaio64*.sys, vbaudio_vmauxvaio*.sys, vbaudio_vmvaio*.sys, and vbaudio_vmvaio3*.sys). The drivers map non-paged pool memory into user space via MmMapLockedPagesSpecifyCache using UserMode access without proper exception handling. If the mapping fails, such as when a process has exhausted available virtual address space, MmMapLockedPagesSpecifyCache raises an exception that is not caught, causing a kernel crash (BSoD), typically SYSTEM_SERVICE_EXCEPTION with STATUS_NO_MEMORY. This flaw allows a local unprivileged user to trigger a denial-of-service on affected Windows systems.

VendorProductVersions

VB-Audio Software

Voicemeeter (Standard)

affected
0 - <= 1.1.1.9

VB-Audio Software

Voicemeeter Banana

affected
0 - <= 2.1.1.9

VB-Audio Software

Voicemeeter Potato

affected
0 - <= 3.1.1.9

VB-Audio Software

Matrix

affected
0 - <= 1.0.2.2

VB-Audio Software

Matrix Coconut

affected
0 - <= 2.0.2.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now