Local Privilege Escalation in CodeMeter Runtime on Windows
Summary
| CVE | CVE-2026-81572 |
|---|---|
| State | PUBLISHED |
| Assigner | wibu |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-27 10:16:39 UTC |
| Updated | 2026-08-27 10:16:39 UTC |
| Description | cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from 2fc02b1f-71e7-4514-a878-169626f68903
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-59 | CWE-59 CWE-59 Improper link resolution before file access ('link following')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 2fc02b1f-71e7-4514-a878-169626f68903 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Wibu-systems-ag | Codemeter-runtime | affected 8.40 8.41a custom | Windows |
| CNA | Wibu-systems-ag | Codemeter-runtime | affected 9.00 9.10 custom | Windows |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| shelltrail.com/research/local-privilege-escalation-to-system-in-wibu-systems... | 2fc02b1f-71e7-4514-a878-169626f68903 | shelltrail.com | |
| cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-103... | 2fc02b1f-71e7-4514-a878-169626f68903 | cdn.wibu.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Andreas Vikerup of Shelltrail AB (en)
There are currently no legacy QID mappings associated with this CVE.