Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81572— Local Privilege Escalation in CodeMeter Runtime on Windows

Quick assessment

Affected
wibu-systems-ag codemeter-runtime
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

当执行 命令时,会在 目录下创建一个可预测的临时文件。在执行文件操作之前,系统未对目录和文件路径进行适当的检查,以判断其是否为 NTFS 重新解析点(如 junction 或符号链接)。本地攻击者可以在该临时文件位置创建一个指向任意系统路径的 junction。由于 CodeMeter 运行时以 System 权限运行,这可能导致攻击者以 System 权限删除任意文件,并有可能实现本地权限提升。

CVSS 7.8 · High

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81572

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Local Privilege Escalation in CodeMeter Runtime on Windows
Source: CVE Program / CVE List V5
Vulnerability Description
cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wibu-systems-ag codemeter-runtime 8.40 ~ 8.41a -

II. Public POCs for CVE-2026-81572

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81572

登录查看更多情报信息。

Vendor Advisories for CVE-2026-81572 (1)

Security Blog Posts for CVE-2026-81572 (1)

Same Patch Batch · wibu-systems-ag · 2026-08-27 · 7 CVEs total

CVE-2026-81581 8.8 HIGH User input in WibuKey is used (without proper sanitization) to compute the address of a po
CVE-2026-81579 8.8 HIGH An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivilege
CVE-2026-81573 8.6 HIGH Improper Access Control in Local-Only Configuration Commands
CVE-2026-81574 8.2 HIGH Format String Vulnerability in Logger
CVE-2026-81576 7.7 HIGH Improper Authentication of Session Handles
CVE-2026-81575 7.5 HIGH Missing Sanity Checks for Buffer Lengths

IV. Related Vulnerabilities

V. Comments for CVE-2026-81572

No comments yet


Leave a comment