QID 378873

QID 378873: Wibu-Systems CodeMeter Runtime Heap Buffer Overflow Vulnerability

CodeMeter is a technology of Wibu-Systems providing secure protection and effective license management of software and digital content.

Affected Versions:
CodeMeter Runtime versions prior to 7.60c

QID Detection Logic (Authenticated and Un-Authenticated):
This checks for vulnerable versions of CodeMeter Runtime.

A heap buffer overflow vulnerability may allow an unauthenticated, remote attacker to achieve RCE (Remote Code Execution) and gain full access of the host system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.6 severity.
  • Solution
    Upgrade to CodeMeter Runtime 7.60c or newer .

    Download here.

    CVEs related to QID 378873

    Software Advisories
    Advisory ID Software Component Link
    WIBU-230704-01 URL Logo cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-230704-01-v3.0.pdf