CVE-2026-81579

Summary

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.

Affected Software

VendorProductVersion RangeStatus
wibu-systems-agwibukey0 < 6.71affected

Weaknesses

  • CWE-123: CWE-123 Write-what-where condition

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References