Impact
A format string flaw exists in the logger of CodeMeter Runtime that fails to sanitize user‑controlled input. When an attacker supplies printf‑style format specifiers, the logger can read arbitrary memory locations, potentially exposing process memory and stack canaries, and can also cause the component to terminate unexpectedly.
Affected Systems
The vulnerability affects Wibu Systems’ CodeMeter Runtime prior to versions 8.41a and 9.10, including the 6.x and 7.x releases. All builds that contain the logger implementation without the input‑sanitization fix are impacted.
Risk and Exploitability
The CVSS score of 8.2 reflects the high impact of the flaw. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. The attack can be launched locally by invoking the cmu --set-proxy command to inject malicious strings, and it can be extended to a remote vector when combined with CVE‑2026‑81573 to alter General.ProxyServer. Successful exploitation results in controlled memory disclosure or denial of service.
OpenCVE Enrichment