PT-2025-21591 · Wibu · Wibu Codemeter
Mateusz Gierblinski
·
Published
2025-05-16
·
Updated
2026-01-13
·
CVE-2025-47809
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Wibu CodeMeter versions prior to 8.30a
Description:
The issue allows for privilege escalation immediately after installation, before a logoff or reboot, under specific conditions. These conditions include an unprivileged installation with UAC and the presence of the CodeMeter Control Center component without it having been restarted. In this scenario, a local user can exploit the issue by navigating from Import License to a privileged instance of Windows Explorer, thus gaining elevated privileges.
Recommendations:
For versions prior to 8.30a, update to version 8.30a or later to resolve the issue.
As a temporary workaround, consider restarting the CodeMeter Control Center component after installation to minimize the risk of exploitation.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wibu Codemeter