Executive brief
CodeMeter Runtime is a licensing and software protection system used to manage and validate software licenses across computers and networks. When configured as a server, the software uses a weak cryptographic method to authenticate session handles, allowing attackers to forge authentication credentials and access license information belonging to other users or systems without proper authorization.
Technical details
When CodeMeter Runtime operates in server mode, it assigns per-connection session identifiers (SIDs) that serve as the sole authentication mechanism for handle authorization. The SIDs are generated using a cryptographically weak algorithm, making them susceptible to brute-force attacks. An unauthenticated attacker on the network can enumerate valid SID values, recover another session's handle number, and access license information associated with that handle. The vulnerability requires the Runtime to be configured as a server and network connectivity to the Runtime Service; no user interaction is required. Fixed in versions 8.41a and 9.10.
Affected products
- Wibu-Systems CodeMeter Runtime before 8.41a and 9.10
Timeline
- 2026-08-27: disclosed