PT-2021-23060 · Wibu · Wibu Codemeter Runtime

Published

2021-10-04

·

Updated

2021-11-17

·

CVE-2021-41057

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WIBU CodeMeter Runtime versions prior to 7.30a
Description The issue allows an attacker to create a crafted CmDongles symbolic link, which will overwrite the linked file without checking permissions.
Recommendations For versions prior to 7.30a, update to version 7.30a or later to resolve the issue.

Fix

Improper Privilege Management

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01770
CVE-2021-41057

Affected Products

Wibu Codemeter Runtime