在 Windows 版 WibuKey 6.71 版本之前,64 位 Windows 系统下的 WibuKey2_64.sys 内核驱动中存在一个不受信任的指针解引用漏洞。攻击者可利用该漏洞实现“写-何处-写何物”(write-what-where)原语,从而进行本地权限提升。该漏洞可被利用来执行任意代码、运行管理员权限的 Shell,或完全控制系统。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wibu-systems-ag | wibukey | 0 ~ 6.71 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81581 | 8.8 HIGH | User input in WibuKey is used (without proper sanitization) to compute the address of a po |
| CVE-2026-81573 | 8.6 HIGH | Improper Access Control in Local-Only Configuration Commands |
| CVE-2026-81574 | 8.2 HIGH | Format String Vulnerability in Logger |
| CVE-2026-81572 | 7.8 HIGH | Local Privilege Escalation in CodeMeter Runtime on Windows |
| CVE-2026-81576 | 7.7 HIGH | Improper Authentication of Session Handles |
| CVE-2026-81575 | 7.5 HIGH | Missing Sanity Checks for Buffer Lengths |
No comments yet