Executive brief
CodeMeter Runtime is a licensing and software protection service used by enterprises to manage and enforce license compliance for protected applications. When running in server mode, the service fails to properly validate data length in certain network requests, allowing a remote attacker to crash the license server, disrupting access to protected software for all connected users.
Technical details
The vulnerability exists in CodeMeter Runtime's handling of opcode 0x5e network requests when the service is configured as a server. The vulnerable code accepts the data length value from the request without proper bounds checking, leading to out-of-bounds memory reads. An unauthenticated remote attacker can craft a malicious request with an oversized data length value to trigger a segmentation fault, causing the entire CodeMeter Runtime service to crash. This results in denial of service affecting all license-dependent applications on network clients. The issue has been patched in versions 8.41a and 9.10.
Affected products
- Wibu-Systems CodeMeter Runtime before 8.41a and 9.10
Timeline
- 2026-08-27: published