Executive brief
WibuKey is a software protection and licensing dongle used to prevent unauthorized software distribution. A flaw in the 64-bit Windows kernel driver allows a local attacker to write arbitrary values to memory, leading to privilege escalation and complete system takeover with administrator privileges. Affected users could lose control of their systems or have malware installed by attackers.
Technical details
The vulnerability is an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows systems, affecting versions before 6.71. This flaw enables a write-what-where primitive that allows local attackers to write arbitrary data to arbitrary memory locations. An attacker with local system access can exploit this to escalate privileges to SYSTEM level, execute arbitrary kernel-mode code, or launch a shell with administrator rights. Mitigation requires upgrading to version 6.71 or later.
Affected products
- Wibu-Systems WibuKey before 6.71
Timeline
- 2026-08-27: disclosed