Filtered by vendor Wibu-systems-ag Subscriptions
Filtered by product Wibukey Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-81579 1 Wibu-systems-ag 1 Wibukey 2026-08-27 8.8 High
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.
CVE-2026-81581 1 Wibu-systems-ag 1 Wibukey 2026-08-27 8.8 High
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits that can cause Remote Code Execution and Privilege Escalation (since the driver runs with system privileges).