PT-2026-82475 · Unknown · Codemeter Runtime

·

CVE-2026-81572

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CodeMeter Runtime (affected versions not specified)
Description The cmu.exe utility creates a predictable temporary file in the C:CM-Stick directory when the --create-io flag is used with the --file parameter. The application fails to properly validate directory and file paths for NTFS reparse points, such as symbolic links or junctions, before performing file operations. A local attacker can create a junction at the temporary file location pointing to an arbitrary system path. Since the process runs with System privileges, this flaw allows for arbitrary file deletion with System privileges, which could lead to local privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81572

Affected Products

Codemeter Runtime