Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe, which allows local users to gain privileges via a Trojan horse file.
CVSS Vector
AV:L/AC:L/Au:N/C:C/I:C/A:CWibu Codemeter Runtime
APPWibu≤ 5.10c
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2023-3935CRITICAL9.8PL ✓same product
Krytyczny heap buffer overflow w Wibu CodeMeter Runtime umożliwiający RCE
CVE-2021-41057HIGH7.1same product
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked f...
CVE-2011-4057MEDIUM5.0same product
Wibu-Systems AG CodeMeter Runtime 4.30c, 4.10b, and possibly other versions before 4.40 allows remote attacker...
CVE-2021-20093CRITICAL9.1PL ✓same vendor
Buffer over-read w Wibu-Systems CodeMeter — ujawnienie pamięci lub crash
CVE-2020-14509CRITICAL9.8PL ✓same vendor
Uszkodzenie pamięci w Wibu CodeMeter — brak walidacji długości pakietów