PT-2026-82481 · Wibukey · Wibukey
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WibuKey versions prior to 6.71
Description
Improper validation of memory boundaries in the
WibuKey64.sys driver allows an attacker to set pointers outside the program scope. This occurs because user input is used without proper sanitization to compute a pointer address, enabling the user to point to any storage location. This typically results in a denial of service, although Remote Code Execution and Privilege Escalation are possible because the driver operates with system privileges.Recommendations
Update WibuKey to version 6.71 or later.
Fix
RCE
DoS
LPE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wibukey