Export limit exceeded: 386826 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-81572 | 2 Wibu-systems-ag, Wibusys | 2 Codemeter-runtime, Codemeter Runtime Kit | 2026-09-04 | 7.8 High |
| In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation. | ||||
| CVE-2026-81575 | 2 Wibu-systems-ag, Wibusys | 2 Codemeter-runtime, Codemeter Runtime Kit | 2026-09-04 | 7.5 High |
| If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime. | ||||
| CVE-2026-81576 | 2 Wibu-systems-ag, Wibusys | 2 Codemeter-runtime, Codemeter Runtime Kit | 2026-09-04 | 7.7 High |
| If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle. | ||||
Page 1 of 1.