As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0333 [1.00] [M/H] Kwetsbaarheden verholpen in CodeMeter Runtime van Wibu-Systems
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0333 [1.00] [M/H] Kwetsbaarheden verholpen in CodeMeter Runtime van Wibu-Systems
Wibu-Systems patched multiple vulnerabilities in CodeMeter Runtime affecting versions 8.41a and 9.10. Flaws include improper NTFS reparse point validation enabling local privilege escalation, inadequate network restrictions in the configuration handler allowing remote unauthorized access to sensitive data, format string injection in the logger module, insufficient bounds checking in opcode requests, and weak authentication that permits brute-force attacks against session handles.
Why it matters: Organizations deploying CodeMeter Runtime should apply patches immediately; local attackers can escalate privileges and remote attackers can access sensitive configuration and WebAdmin controls, directly compromising license management and system integrity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0333 [1.00] [M/H] Kwetsbaarheden verholpen in CodeMeter Runtime van Wibu-Systems
Wibu-Systems patched multiple vulnerabilities in CodeMeter Runtime affecting versions 8.41a and 9.10. Flaws include improper NTFS reparse point validation enabling local privilege escalation, inadequate network restrictions in the configuration handler allowing remote unauthorized access to sensitive data, format string injection in the logger module, insufficient bounds checking in opcode requests, and weak authentication that permits brute-force attacks against session handles.
Why it matters: Organizations deploying CodeMeter Runtime should apply patches immediately; local attackers can escalate privileges and remote attackers can access sensitive configuration and WebAdmin controls, directly compromising license management and system integrity.
- Source published
- First seen by Cybersecurity Tracker