Vulnerabilidad · Publicado 27/08/2026
Se descubrió una validación deficiente de límites de memoria en WibuKey versión 6.70 y anteriores para Windows, que permite a atacantes manipular punteros y ejecutar código con privilegios de sistema. La vulnerabilidad afecta principalmente a empresas que utilizan soluciones de licenciamiento Wibu-Systems en México y Latinoamérica, exponiendo servidores y estaciones de trabajo a denegación de servicio, escalada de privilegios y potencial ejecución remota de código.
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits that can cause Remote Code Execution and Privilege Escalation (since the driver runs with system privileges).
Score: 8.8/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-119
Publicado en NIST NVD.