PT-2026-82475 · Unknown · Codemeter Runtime
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CodeMeter Runtime (affected versions not specified)
Description
The
cmu.exe utility creates a predictable temporary file in the C:CM-Stick directory when the --create-io flag is used with the --file parameter. The application fails to properly validate directory and file paths for NTFS reparse points, such as symbolic links or junctions, before performing file operations. A local attacker can create a junction at the temporary file location pointing to an arbitrary system path. Since the process runs with System privileges, this flaw allows for arbitrary file deletion with System privileges, which could lead to local privilege escalation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codemeter Runtime