Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2rfr-r5fg-2857

Опубликовано: 16 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.

EPSS

Процентиль: 4%
0.0002
Низкий

8.2 High

CVSS3

Дефекты

CWE-272

Связанные уязвимости

CVSS3: 8.2
nvd
9 месяцев назад

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.

EPSS

Процентиль: 4%
0.0002
Низкий

8.2 High

CVSS3

Дефекты

CWE-272