cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and
file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file
operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary
system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted
with System privileges and potentially enable local privilege escalation.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation. | |
| Title | Local Privilege Escalation in CodeMeter Runtime on Windows | |
| First Time appeared |
Wibu-systems-ag
Wibu-systems-ag codemeter-runtime |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:wibu-systems-ag:codemeter-runtime:*:*:windows:*:*:*:*:* | |
| Vendors & Products |
Wibu-systems-ag
Wibu-systems-ag codemeter-runtime |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: wibu
Published: 2026-08-27T07:06:17.884Z
Updated: 2026-08-27T13:36:14.915Z
Reserved: 2026-08-27T07:01:24.780Z
Link: CVE-2026-81572
Updated: 2026-08-27T13:36:04.395Z
Status : Received
Published: 2026-08-27T10:16:39.810
Modified: 2026-08-27T10:16:39.810
Link: CVE-2026-81572
No data.