8.2highHigh

CVE-2025-47809

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an administrative account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
8.2 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness
CWE-272
Assigned by
cve@mitre.org

Dates

Published
2025-05-16
Last modified
2026-09-08
Sources
NVD

References