PT-2025-21591 · Wibu · Wibu Codemeter

Mateusz Gierblinski

·

Published

2025-05-16

·

Updated

2026-01-13

·

CVE-2025-47809

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Wibu CodeMeter versions prior to 8.30a
Description: The issue allows for privilege escalation immediately after installation, before a logoff or reboot, under specific conditions. These conditions include an unprivileged installation with UAC and the presence of the CodeMeter Control Center component without it having been restarted. In this scenario, a local user can exploit the issue by navigating from Import License to a privileged instance of Windows Explorer, thus gaining elevated privileges.
Recommendations: For versions prior to 8.30a, update to version 8.30a or later to resolve the issue. As a temporary workaround, consider restarting the CodeMeter Control Center component after installation to minimize the risk of exploitation.

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-47809

Affected Products

Wibu Codemeter