Description
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.
Published: 2026-08-27
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64‑bit Windows. This flaw provides a write‑what‑where primitive that can be used to execute arbitrary code in kernel mode, allowing an attacker to spawn an administrator shell and gain full system control. The weakness is captured by CWE‑123 and carries a CVSS score of 8.8, indicating a high impact if successfully exploited.

Affected Systems

The affected product is WibuKey for Windows before version 6.71, specifically the kernel driver wibuKey2_64.sys provided by Wibu‑Systems AG. The vulnerability applies to 64‑bit Windows operating systems running the compromised driver.

Risk and Exploitability

Although the EPSS score is not available, the lack of a KEV listing does not reduce the risk, because the flaw permits local privilege escalation and has a high CVSS rating. The likely attack vector is an authenticated local user with access to the affected system, who may exploit the driver to gain kernel privileges. Once the exploit is triggered, the attacker can execute arbitrary code with SYSTEM rights, effectively compromising the entire machine.

Generated by OpenCVE AI on August 27, 2026 at 10:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WibuKey to version 6.71 or later to apply the vendor patch.
  • If upgrading is not immediately possible, limit local users to the least privilege necessary and isolate vulnerable machines from critical infrastructure.
  • Apply continuous monitoring of system logs for anomalous kernel driver activity to detect potential exploitation attempts.

Generated by OpenCVE AI on August 27, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.
Title An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivileged user on Windows
First Time appeared Wibu-systems-ag
Wibu-systems-ag wibukey
Weaknesses CWE-123
CPEs cpe:2.3:a:wibu-systems-ag:wibukey:*:*:*:*:*:*:*:*
Vendors & Products Wibu-systems-ag
Wibu-systems-ag wibukey
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Wibu-systems-ag Wibukey
cve-icon MITRE

Status: PUBLISHED

Assigner: wibu

Published:

Updated: 2026-08-27T08:49:17.321Z

Reserved: 2026-08-27T07:34:49.654Z

Link: CVE-2026-81579

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T10:16:40.457

Modified: 2026-08-27T10:16:40.457

Link: CVE-2026-81579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T10:45:17Z

Weaknesses
  • CWE-123

    Write-what-where Condition