当执行 命令时,会在 目录下创建一个可预测的临时文件。在执行文件操作之前,系统未对目录和文件路径进行适当的检查,以判断其是否为 NTFS 重新解析点(如 junction 或符号链接)。本地攻击者可以在该临时文件位置创建一个指向任意系统路径的 junction。由于 CodeMeter 运行时以 System 权限运行,这可能导致攻击者以 System 权限删除任意文件,并有可能实现本地权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wibu-systems-ag | codemeter-runtime | 8.40 ~ 8.41a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81581 | 8.8 HIGH | User input in WibuKey is used (without proper sanitization) to compute the address of a po |
| CVE-2026-81579 | 8.8 HIGH | An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivilege |
| CVE-2026-81573 | 8.6 HIGH | Improper Access Control in Local-Only Configuration Commands |
| CVE-2026-81574 | 8.2 HIGH | Format String Vulnerability in Logger |
| CVE-2026-81576 | 7.7 HIGH | Improper Authentication of Session Handles |
| CVE-2026-81575 | 7.5 HIGH | Missing Sanity Checks for Buffer Lengths |
No comments yet