Executive brief
WibuKey is a software protection and licensing dongle used by enterprises to secure and monetize software products. A flaw in the WibuKey64.sys driver allows attackers to manipulate memory pointers, potentially causing service disruptions or worse. Since the driver operates with system-level privileges, successful exploitation could enable attackers to execute code with the highest privileges on affected computers.
Technical details
The vulnerability is an improper validation of memory boundaries in the WibuKey64.sys kernel driver affecting WibuKey up to version 6.70 on Windows. An attacker can exploit this by setting pointers outside the allocated program scope, leading to out-of-bounds memory access. The attack vector is local and does not require elevated privileges to trigger. While the immediate impact is denial of service, the driver's system-level execution context creates potential for privilege escalation and remote code execution. Patches are expected from Wibu-Systems for affected versions.
Affected products
- Wibu-Systems WibuKey up to 6.70
Timeline
- 2026-08-27: disclosed