当 CodeMeter Runtime 被配置为服务器时,8.41a 及 9.10 之前的版本会接收包含数据长度和数据内容的数据包(opcode 为 0x5e)。由于对“数据长度”字段缺少边界检查,可能导致越界读取,从而引发内存访问错误(segmentation fault),最终导致 CodeMeter Runtime 崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wibu-systems-ag | codemeter-runtime | 9.00 ~ 9.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81581 | 8.8 HIGH | User input in WibuKey is used (without proper sanitization) to compute the address of a po |
| CVE-2026-81579 | 8.8 HIGH | An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivilege |
| CVE-2026-81573 | 8.6 HIGH | Improper Access Control in Local-Only Configuration Commands |
| CVE-2026-81574 | 8.2 HIGH | Format String Vulnerability in Logger |
| CVE-2026-81572 | 7.8 HIGH | Local Privilege Escalation in CodeMeter Runtime on Windows |
| CVE-2026-81576 | 7.7 HIGH | Improper Authentication of Session Handles |
No comments yet