IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-331739: Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting Siemens Products

HIGH
CVSS 8.2
Date 2026-09-08T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

WIBU Systems published information about a privilege escalation vulnerability under a certain circumstances and associated fix releases of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens industrial products. Siemens has released new versions for the affected products and recommends to update to the latest versions.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2025-47809 8.2 high
CVE-2025-47809. Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.

// Affected Products (3)

Vendor Product Asset Type Purdue Level Firmware
Siemens Unknown hmi
L2
--
Siemens Unknown hmi
L2
--
Siemens Unknown hmi
L2
--

// Remediations (14)

Patch: Update to V3.18 P032 or later version
Update to V3.18 P032 or later version
Patch: Apply patch as documented in section 'Additional Information'
Apply patch as documented in section 'Additional Information'
Patch: Update to V8.0 QU2 or later version
Update to V8.0 QU2 or later version
Patch: Update to V8.0 QU2 or later version
Update to V8.0 QU2 or later version
Patch: Update to V3.19 P020 or later version
Update to V3.19 P020 or later version
Patch: Update to V3.20 P008 or later version
Update to V3.20 P008 or later version
Patch: Update to V5.0 SP2 or later version
Update to V5.0 SP2 or later version
Patch: Apply patch as documented in section 'Additional Information'
Apply patch as documented in section 'Additional Information'
Patch: Update to V3.18 P032 or later version
Update to V3.18 P032 or later version
Patch: Update to V3.20 P008 or later version
Update to V3.20 P008 or later version
Patch: Update to V3.19 P020 or later version
Update to V3.19 P020 or later version
Patch: Apply patch as documented in section 'Additional Information'
Apply patch as documented in section 'Additional Information'
Patch: Update to V8.0 QU2 or later version
Update to V8.0 QU2 or later version
Patch: Update to V8.0 QU2 or later version
Update to V8.0 QU2 or later version

// References