silabser.sys - Clean (18/100) - DriverShield Analysis

Analysis of silabser.sys: clean verdict, risk score 18/100. 0 YARA matches, 0/76 multi-engine detections. SHA256 ca644642c189a216. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

silabser.sys - Analysis Report

DriverShield analyzed the Windows kernel driver silabser.sys and assigned a verdict of Clean with a composite risk score of 18/100, indicating no notable risk signals (0-29 band).

VerdictClean (18/100)
YARA matches0
Multi-engine detections0 / 76
File size156904 bytes
Code-signing signerDigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Analyzed2026-05-01
SHA256ca644642c189a216d67e4073f099a8768811d93a0257efd48dc3fc687a9390af
SHA1006b0ab22ea64d88aaca673a6f61cf318e1aef46
MD57704049b5600ce715de9faea36a6bd97

Driver identity

Version resource data embedded in the silabser.sys PE header, as extracted by the analysis engine.

File descriptionSilicon Labs CP210x USB to UART Bridge Universal Driver (64-bit)
ProductSilicon Labs USBXpress Software
CompanySilicon Laboratories Inc.
Original filenamesilabser.sys
Internal namesilabser
File version11.5.0.417
CopyrightCopyright © 2019 Silicon Laboratories Inc., All Rights Reserved.

How the 18/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches0 / 100
Dangerous kernel imports30 / 100
IOCTL dispatch surface100 / 100
Known-vulnerable corpus0 / 100
Code-signing state0 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

Kernel imports (7)

Kernel-mode APIs resolved from the Import Address Table of silabser.sys, ranked by exploitation relevance.

APIRiskWhy it matters
MmGetSystemRoutineAddresshighPotentially dangerous - could be used for privilege escalation or security bypass
IofCompleteRequestlowStandard kernel API - generally benign
ExAllocatePoolWithTaglowStandard kernel API - generally benign
ExAllocatePool2lowStandard kernel API - generally benign
DbgPrintExlowStandard kernel API - generally benign
KeDelayExecutionThreadlowStandard kernel API - generally benign
RtlInitUnicodeStringlowStandard kernel API - generally benign

IOCTL dispatch codes (34)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x0080908BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1058
0x0080868BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #418
0x0080878BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #482
0x0080888BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #546
0x0080808BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #34
0x00808D8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #866
0x002200F0mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #60
0x00227FE8mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #4090
0x008091B6mediumMETHOD_OUT_DIRECTFILE_DEVICE_CUSTOM Function #1133
0x00808B48mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #722
0x00342BE8mediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #2810
0x0022BE38mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #3982
0x0080EC81mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #2848
0x002227E8mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #2554
0x00808E8AmediumMETHOD_OUT_DIRECTFILE_DEVICE_CUSTOM Function #930
0x0022200CmediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #2051
0x0022208CmediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #2083
0x00808B8AmediumMETHOD_OUT_DIRECTFILE_DEVICE_CUSTOM Function #738
0x0080BF80mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #4064
0x008000B8mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #46
0x0034BBE8mediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #3834
0x0080B841mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #3600
0x0080BF00mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #4032
0x0080007EmediumMETHOD_OUT_DIRECTFILE_DEVICE_CUSTOM Function #31

Showing 24 of 34 extracted control codes.

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0x1650F0x166006.5CODE, EXEC, READ
.rdata0x18240x1A005.14IDATA, READ
.data0x04880x02002.03IDATA, READ, WRITE
.pdata0x09FC0x0A004.96IDATA, READ
PAGESRP00x63EC0x64006.4CODE, EXEC, READ
PAGE0x03AD0x04005.92CODE, EXEC, READ
PAGESER0x063A0x08005.31CODE, EXEC, READ
INIT0x0C980x0E005.44CODE, EXEC, READ, DISCARD
.rsrc0x04300x06002.56IDATA, READ, DISCARD
.reloc0x00580x02001.17IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardEnabled
ASLREnabled
DEPEnabled
Integrity checkNot enforced
Mitigation score100 / 100

MITRE ATT&CK techniques (6)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1071Application Layer ProtocolCommand and Control
T1211Exploitation for Defense EvasionDefense Evasion
T1543.003Windows ServicePersistence
T1553.002Subvert Trust Controls: Code SigningDefense Evasion
T1569.002Service ExecutionExecution
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerDigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Signer organisationDigiCert, Inc.
IssuerDigiCert Trusted Root G4
Serial8AD40B260D29C4C9F5ECDA9BD93AED9
Valid from2021-04-29 00:00 UTC
Valid until2036-04-28 23:59 UTC
Signature validityVerified

Symbolic execution

Engine angr, status completed, 51 paths explored at a maximum depth of 51. Vulnerability classes reached: 0. Exploitable paths: 2.

Frequently asked questions about silabser.sys

Is silabser.sys safe?

Based on DriverShield static and dynamic analysis, silabser.sys is assessed as clean, with no notable risk signals. Its composite risk score is 18/100 (verdict: clean). Always validate findings independently before acting.

What is the risk score of silabser.sys?

silabser.sys has a DriverShield composite risk score of 18/100, placing it in the clean verdict band. SHA256: ca644642c189a216d67e4073f099a8768811d93a0257efd48dc3fc687a9390af.

What is silabser.sys?

silabser.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1.

Related: Other drivers signed by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 · What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact