CVE-2026-81579 PUBLISHED

An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivileged user on Windows

Assigner: wibu
Reserved: 27.08.2026 Published: 27.08.2026 Updated: 27.08.2026

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor wibu-systems-ag
Product wibukey
Versions Default: unaffected
  • affected from 0 to 6.71 (excl.)

Credits

  • 김명규 working with Trend Micro Zero Day Initiative reporter

References

Problem Types

  • CWE-123 Write-what-where condition CWE