{"api_version":"1","generated_at":"2026-09-11T19:43:10+00:00","cve":"CVE-2025-47809","urls":{"html":"https://cve.report/CVE-2025-47809","api":"https://cve.report/api/cve/CVE-2025-47809.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-47809","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-47809"},"summary":{"title":"CVE-2025-47809","description":"Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.","state":"PUBLISHED","assigner":"mitre","published_at":"2025-05-16 01:15:51","updated_at":"2026-09-08 09:17:37"},"problem_types":["CWE-272","CWE-272 CWE-272 Least Privilege Violation"],"metrics":[{"version":"3.1","source":"cve@mitre.org","type":"Secondary","score":"8.2","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.2","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-331739.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-331739.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-201595.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-201595.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.wibu.com/support/security-advisories/wibu-100120.html","name":"https://www.wibu.com/support/security-advisories/wibu-100120.html","refsource":"cve@mitre.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-47809","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47809","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Wibu","product":"CodeMeter","version":"affected 8.30a custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"Desigo CC family V5.0","version":"affected * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"Desigo CC family V5.1","version":"affected * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"Desigo CC family V6","version":"affected * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"Desigo CC family V7","version":"affected * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"Desigo CC family V8","version":"affected V8.0 QU2 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SENTRON Powermanager V5","version":"affected * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SENTRON Powermanager V6","version":"affected * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SENTRON Powermanager V7","version":"affected * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SENTRON Powermanager V8","version":"affected V8.0 QU2 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC PDM Maintenance Station V5.0","version":"affected V5.0 SP2 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC WinCC OA V3.18","version":"affected V3.18 P032 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC WinCC OA V3.19","version":"affected V3.19 P020 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC WinCC OA V3.20","version":"affected V3.20 P008 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-47809","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-05-16T13:35:54.604112Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-05-16T13:36:00.498Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"affected":[{"defaultStatus":"unknown","product":"Desigo CC family V5.0","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"Desigo CC family V5.1","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"Desigo CC family V6","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"Desigo CC family V7","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"Desigo CC family V8","vendor":"Siemens","versions":[{"lessThan":"V8.0 QU2","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SENTRON Powermanager V5","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SENTRON Powermanager V6","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SENTRON Powermanager V7","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SENTRON Powermanager V8","vendor":"Siemens","versions":[{"lessThan":"V8.0 QU2","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC PDM Maintenance Station V5.0","vendor":"Siemens","versions":[{"lessThan":"V5.0 SP2","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC WinCC OA V3.18","vendor":"Siemens","versions":[{"lessThan":"V3.18 P032","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC WinCC OA V3.19","vendor":"Siemens","versions":[{"lessThan":"V3.19 P020","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC WinCC OA V3.20","vendor":"Siemens","versions":[{"lessThan":"V3.20 P008","status":"affected","version":"0","versionType":"custom"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T08:42:59.701Z","orgId":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","shortName":"siemens-SADP"},"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-331739.html"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-201595.html"}],"x_adpType":"supplier"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"CodeMeter","vendor":"Wibu","versions":[{"lessThan":"8.30a","status":"affected","version":"0","versionType":"custom"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:wibu:codemeter:*:*:*:*:*:*:*:*","versionEndExcluding":"8.30a","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer."}],"metrics":[{"cvssV3_1":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-272","description":"CWE-272 Least Privilege Violation","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-05-16T00:18:40.444Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"url":"https://www.wibu.com/support/security-advisories/wibu-100120.html"}],"x_generator":{"engine":"enrichogram 0.0.1"}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2025-47809","datePublished":"2025-05-16T00:00:00.000Z","dateReserved":"2025-05-10T00:00:00.000Z","dateUpdated":"2026-09-08T08:42:59.701Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-05-16 01:15:51","lastModifiedDate":"2026-09-08 09:17:37","problem_types":["CWE-272","CWE-272 CWE-272 Least Privilege Violation"],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.5,"impactScore":6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-16T13:35:54.604112Z","id":"CVE-2025-47809","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"47809","Ordinal":"1","Title":"CVE-2025-47809","CVE":"CVE-2025-47809","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"47809","Ordinal":"1","NoteData":"Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.","Type":"Description","Title":"CVE-2025-47809"}]}}}