CVE-2024-9497: Silabs.com Usbxpress 4 SDK

High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

Affected products

  • Silabs.com Usbxpress 4 SDK: up to and including 4.0.3

Published 2025-01-24. Last modified 2026-06-17.