Impact
An identified flaw in CodeMeter Runtime allows a local attacker to create a predictable temporary file within the \'C:\CM-Stick\' directory. Because the application does not validate NTFS reparse points, a malicious user can construct a junction or symbolic link that redirects file operations to arbitrary system paths. When CodeMeter Runtime, running with System privileges, performs these operations, it can delete any file at the resolved location, thereby elevating the attacker's privileges on the system.
Affected Systems
The vulnerability affects the CodeMeter Runtime product from Wibu Systems AG, which operates on Windows platforms. Specific version information was not disclosed by the CNA. Users running any installations of this runtime on Windows are potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 classifies this flaw as High severity. The EPSS score is not available, making it unclear how often exploitation occurs currently, and the vulnerability is not listed in the CISA KEV catalog. The attack requires local access and the ability to create NTFS junctions; once the attacker controls this path manipulation, they can delete files with System-level rights, potentially enabling full local privilege escalation. Given the lack of a publicly disclosed exploit, the likelihood is uncertain, yet the high impact warrants pre‑emptive action.
OpenCVE Enrichment