IM
IronMonkey Threat Research

CVE-2025-47809 HIGH

Published: 2025-05-16 | Last Modified: 2026-09-08 | Status: Deferred

Description

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.

Additional Descriptions (1)

Las versiones anteriores a la versión 8.30a de Wibu CodeMeter a veces permiten la escalada de privilegios inmediatamente después de la instalación (antes de cerrar sesión o reiniciar). Para que esto ocurra, debe haber una instalación sin privilegios con Control de cuentas de usuario (UAC), y el componente CodeMeter Control Center debe estar instalado y no debe haberse reiniciado. En este caso, el usuario local puede acceder desde Importar licencia a una instancia privilegiada del Explorador de Windows.

CVSS Metrics

Base Score: 8.2 (HIGH)

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 1.5

Impact Score: 6.0

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-272
Notification
Message here