Impact
The vulnerability is an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64‑bit Windows. This flaw provides a write‑what‑where primitive that can be used to execute arbitrary code in kernel mode, allowing an attacker to spawn an administrator shell and gain full system control. The weakness is captured by CWE‑123 and carries a CVSS score of 8.8, indicating a high impact if successfully exploited.
Affected Systems
The affected product is WibuKey for Windows before version 6.71, specifically the kernel driver wibuKey2_64.sys provided by Wibu‑Systems AG. The vulnerability applies to 64‑bit Windows operating systems running the compromised driver.
Risk and Exploitability
Although the EPSS score is not available, the lack of a KEV listing does not reduce the risk, because the flaw permits local privilege escalation and has a high CVSS rating. The likely attack vector is an authenticated local user with access to the affected system, who may exploit the driver to gain kernel privileges. Once the exploit is triggered, the attacker can execute arbitrary code with SYSTEM rights, effectively compromising the entire machine.
OpenCVE Enrichment