Impact
The flaw involves CodeMeter Runtime creating a predictable temporary file when cmu.exe is run with the parameters --create-io --file C:. The application does not properly validate NTFS reparse points such as junctions or symbolic links before performing file operations, allowing a local attacker to craft a junction that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, the attacker can delete any file at the resolved location, enabling arbitrary file deletion and local privilege escalation.
Affected Systems
The vulnerability affects Wibu Systems AG’s CodeMeter Runtime product for Windows. Versions 8.40 through (but not including) 8.41a and 9.00 through (but not including) 9.10 are impacted; any installation of these versions running with System privileges is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 classifies this flaw as High severity. The EPSS score of 0.00166 (<1%) indicates a very low probability of exploitation, but the vulnerability is not listed in the CISA KEV catalog. The attack requires local access and the ability to create NTFS junctions; once the attacker controls this path manipulation, they can delete files with System-level rights, potentially enabling full local privilege escalation. Given the lack of a publicly disclosed exploit, the likelihood is uncertain, yet the high impact warrants pre‑emptive action.
OpenCVE Enrichment