Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe, which allows local users to gain privileges via a Trojan horse file.
oryginał ENCVSS Vector
AV:L/AC:L/Au:N/C:C/I:C/A:CWibu Codemeter Runtime
APPWibu≤ 5.10c
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2023-3935CRITICAL9.8PL ✓ten sam produkt
Krytyczny heap buffer overflow w Wibu CodeMeter Runtime umożliwiający RCE
CVE-2021-41057HIGH7.1ten sam produkt
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked f...
CVE-2011-4057MEDIUM5.0ten sam produkt
Wibu-Systems AG CodeMeter Runtime 4.30c, 4.10b, and possibly other versions before 4.40 allows remote attacker...
CVE-2021-20093CRITICAL9.1PL ✓ten sam vendor
Buffer over-read w Wibu-Systems CodeMeter — ujawnienie pamięci lub crash
CVE-2020-14509CRITICAL9.8PL ✓ten sam vendor
Uszkodzenie pamięci w Wibu CodeMeter — brak walidacji długości pakietów