CVE-2026-23761: CWE-824 Access of Uninitialized Pointer in VB-Audio Software Voicemeeter (Standard)
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers (vbvoicemeetervaio64*.sys, vbmatrixvaio64*.sys, vbaudio_vmauxvaio*.sys, vbaudio_vmvaio*.sys, and vbaudio_vmvaio3*.sys). When a handle is opened with a special file attribute value, the drivers improperly initialize FILE_OBJECT->FsContext to a non-pointer magic value. If subsequent operations are not handled by the VB-Audio driver and are forwarded down the audio driver stack (e.g., via PortCls to ks.sys), the invalid FsContext value can be dereferenced, causing a kernel crash (BSoD), typically SYSTEM_SERVICE_EXCEPTION with STATUS_ACCESS_VIOLATION. This flaw allows a local unprivileged user to trigger a denial-of-service on affected Windows systems.
AI Analysis
Technical Summary
CVE-2026-23761 is a vulnerability in VB-Audio Software's Voicemeeter (Standard), Voicemeeter Banana, Voicemeeter Potato, and VB-Audio Matrix products affecting their virtual audio drivers. The issue arises when a handle is opened with a special file attribute, causing the driver to improperly initialize the FILE_OBJECT->FsContext field to a non-pointer magic value. If subsequent operations are forwarded down the audio driver stack (e.g., via PortCls to ks.sys), the invalid FsContext pointer can be dereferenced, resulting in a kernel crash (BSoD) with SYSTEM_SERVICE_EXCEPTION and STATUS_ACCESS_VIOLATION. This vulnerability enables a local unprivileged user to trigger a denial-of-service condition on Windows systems running affected driver versions. The CVSS 4.0 vector indicates local attack vector, low attack complexity, no privileges required, no user interaction, and high impact on availability.
Potential Impact
The vulnerability allows a local unprivileged user to cause a denial-of-service by triggering a kernel crash (Blue Screen of Death) on affected Windows systems running vulnerable versions of VB-Audio's virtual audio drivers. This results in system instability and potential disruption of audio services. There is no indication of code execution or privilege escalation from the provided data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or fix information is provided, users should monitor VB-Audio Software's advisories for updates. Until a fix is available, restricting local unprivileged user access to affected systems may reduce risk. No vendor advisory states that no action is required or that the issue is mitigated.
CVE-2026-23761: CWE-824 Access of Uninitialized Pointer in VB-Audio Software Voicemeeter (Standard)
Description
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers (vbvoicemeetervaio64*.sys, vbmatrixvaio64*.sys, vbaudio_vmauxvaio*.sys, vbaudio_vmvaio*.sys, and vbaudio_vmvaio3*.sys). When a handle is opened with a special file attribute value, the drivers improperly initialize FILE_OBJECT->FsContext to a non-pointer magic value. If subsequent operations are not handled by the VB-Audio driver and are forwarded down the audio driver stack (e.g., via PortCls to ks.sys), the invalid FsContext value can be dereferenced, causing a kernel crash (BSoD), typically SYSTEM_SERVICE_EXCEPTION with STATUS_ACCESS_VIOLATION. This flaw allows a local unprivileged user to trigger a denial-of-service on affected Windows systems.
CVSS v4.0
Score 6.9medium
Affected software
VB-Audio Software
Voicemeeter (Standard)
VB-Audio Software
Voicemeeter Banana
VB-Audio Software
Voicemeeter Potato
VB-Audio Software
Matrix
VB-Audio Software
Matrix Coconut
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-23761 is a vulnerability in VB-Audio Software's Voicemeeter (Standard), Voicemeeter Banana, Voicemeeter Potato, and VB-Audio Matrix products affecting their virtual audio drivers. The issue arises when a handle is opened with a special file attribute, causing the driver to improperly initialize the FILE_OBJECT->FsContext field to a non-pointer magic value. If subsequent operations are forwarded down the audio driver stack (e.g., via PortCls to ks.sys), the invalid FsContext pointer can be dereferenced, resulting in a kernel crash (BSoD) with SYSTEM_SERVICE_EXCEPTION and STATUS_ACCESS_VIOLATION. This vulnerability enables a local unprivileged user to trigger a denial-of-service condition on Windows systems running affected driver versions. The CVSS 4.0 vector indicates local attack vector, low attack complexity, no privileges required, no user interaction, and high impact on availability.
Potential Impact
The vulnerability allows a local unprivileged user to cause a denial-of-service by triggering a kernel crash (Blue Screen of Death) on affected Windows systems running vulnerable versions of VB-Audio's virtual audio drivers. This results in system instability and potential disruption of audio services. There is no indication of code execution or privilege escalation from the provided data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or fix information is provided, users should monitor VB-Audio Software's advisories for updates. Until a fix is available, restricting local unprivileged user access to affected systems may reduce risk. No vendor advisory states that no action is required or that the issue is mitigated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-01-15T18:42:20.938Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 697251f54623b1157c7bcf88
Added to database: 01/22/2026, 16:36:05 UTC
Last enriched: 05/14/2026, 02:09:05 UTC
Last updated: 09/10/2026, 22:21:46 UTC
Views: 249
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.