cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation.
History

Thu, 27 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation.
Title Local Privilege Escalation in CodeMeter Runtime on Windows
First Time appeared Wibu-systems-ag
Wibu-systems-ag codemeter-runtime
Weaknesses CWE-59
CPEs cpe:2.3:a:wibu-systems-ag:codemeter-runtime:*:*:windows:*:*:*:*:*
Vendors & Products Wibu-systems-ag
Wibu-systems-ag codemeter-runtime
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: wibu

Published: 2026-08-27T07:06:17.884Z

Updated: 2026-08-27T13:36:14.915Z

Reserved: 2026-08-27T07:01:24.780Z

Link: CVE-2026-81572

cve-icon Vulnrichment

Updated: 2026-08-27T13:36:04.395Z

cve-icon NVD

Status : Received

Published: 2026-08-27T10:16:39.810

Modified: 2026-08-27T10:16:39.810

Link: CVE-2026-81572

cve-icon Redhat

No data.