Impact
The vulnerability is an improper validation of memory boundaries in the WibuKey64.sys driver, allowing an attacker to set pointers that fall outside the program’s allocated space. When such pointers are used, Windows responds with a denial of service. Because the driver runs with system privileges, the flaw could also enable remote code execution or privilege escalation, although such outcomes have not yet been demonstrated.
Affected Systems
Vendor WibuSystems sells the WibuKey license manager for Windows. Versions of WibuKey up to and including 6.70 contain the flaw. The issue is confined to the driver component WibuKey64.sys, which is installed with the WibuKey package.
Risk and Exploitability
The CVSS v3.1 score of 8.8 indicates a high impact, and the absence of an EPSS score suggests that the likelihood of exploitation is not currently quantified. The vulnerability is not listed in the CISA KEV catalog. An attacker with local access or the ability to craft malicious input to the driver can trigger the out‑of‑bounds pointer, leading to an immediate denial of service. Because the driver runs as SYSTEM, a successful exploitation could potentially allow code execution with elevated privileges, depending on the attacker’s ability to further manipulate the driver’s execution flow.
OpenCVE Enrichment