CVE-2026-81579 HIGH

CVE-2026-81579: An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivileged user on Windows

Vendor Wibu-Systems-Ag
Product wibukey
Weakness CWE-123
Published August 27, 2026
Last update August 28, 2026

CVSS base score

8.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated