在 CodeMeter Runtime 8.41a 和 9.10 版本之前,日志记录器在特定情况下未对输入字符串进行净化处理,使得攻击者能够注入 printf 风格的格式说明符。这一缺陷可被利用来可靠地导致 CodeMeter 崩溃,并泄露进程内存和栈金丝雀等敏感信息。该攻击可在本地执行,例如通过 设置代理值;也可在远程环境中,结合 CVE-2026-81573(通过设置 General.ProxyServer 后触发该漏洞)实现。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wibu-systems-ag | codemeter-runtime | 9.00 ~ 9.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81581 | 8.8 HIGH | User input in WibuKey is used (without proper sanitization) to compute the address of a po |
| CVE-2026-81579 | 8.8 HIGH | An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivilege |
| CVE-2026-81573 | 8.6 HIGH | Improper Access Control in Local-Only Configuration Commands |
| CVE-2026-81572 | 7.8 HIGH | Local Privilege Escalation in CodeMeter Runtime on Windows |
| CVE-2026-81576 | 7.7 HIGH | Improper Authentication of Session Handles |
| CVE-2026-81575 | 7.5 HIGH | Missing Sanity Checks for Buffer Lengths |
No comments yet