Wibu
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Wibu product.
RSS Feeds for Wibu security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Wibu products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Wibu Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 2 vulnerabilities in Wibu with an average score of 7.8 out of ten. Last year, in 2025 Wibu had 1 security vulnerability published. That is, 1 more vulnerability have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.40
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 7.80 |
| 2025 | 1 | 8.20 |
| 2024 | 2 | 6.65 |
| 2023 | 2 | 9.80 |
| 2022 | 0 | 0.00 |
| 2021 | 2 | 0.00 |
| 2020 | 2 | 9.80 |
It may take a day or so for new Wibu vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Wibu Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2020-37017 | Jan 29, 2026 |
CodeMeter 6.60 Unquoted Service Path Exec Priv EscCodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CodeMeter Runtime Server service to inject malicious code that would execute with LocalSystem permissions. |
|
| CVE-2021-47810 | Jan 15, 2026 |
Unquoted Service Path Vulnerability in WibuKey Runtime 6.51 (WkSvW32.exe)WibuKey Runtime 6.51 contains an unquoted service path vulnerability in the WkSvW32.exe service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\PROGRAM FILES (X86)\WIBUKEY\SERVER\WkSvW32.exe' to inject malicious executables and escalate privileges. |
|
| CVE-2025-47809 | May 16, 2025 |
Wibu CodeMeter <8.30a Priv Esc via Control CenterWibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer. |
|
| CVE-2024-45182 | Sep 12, 2024 |
WibuKey <=6.69 Bounds Check in WibuKey64.sys Enables DoSAn issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary address read, resulting in Denial of Service. |
|
| CVE-2024-45181 | Sep 12, 2024 |
Kernel Mem Corruption in WibuKey64.sys before v6.70An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70. An improper bounds check allows crafted packets to cause an arbitrary address write, resulting in kernel memory corruption. |
|
| CVE-2023-4701 | Sep 13, 2023 |
REJECTED: CVE-2023-4701 duplicate of CVE-2023-3935** REJECT ** This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the vendor eventually states that this issue is identical to CVE-2023-3935 |
|
| CVE-2023-3935 | Sep 13, 2023 |
CodeMeter Runtime <=7.60b Heap Buffer Overflow RCEA heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. |
|
| CVE-2021-20094 | Jun 16, 2021 |
A denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21aA denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to crash the CodeMeter Runtime Server. |
|
| CVE-2021-20093 | Jun 16, 2021 |
A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21aA buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server. |
|
| CVE-2020-14517 | Sep 16, 2020 |
Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which mayProtocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API. |
|