CVE-2026-81579
8.8Wibu-Systems · WibuKey
A kernel driver vulnerability in WibuKey for Windows allows local users to achieve privilege escalation via an untrusted pointer dereference leading to a write-what-where primitive.
Executive summary
An untrusted pointer dereference in the WibuKey kernel driver allows local attackers to gain full administrative control over affected Windows systems.
Vulnerability
This vulnerability resides in the WibuKey2_64.sys kernel driver for 64-bit Windows, where an untrusted pointer dereference occurs. An attacker with local access can exploit this to achieve a write-what-where condition, enabling arbitrary code execution with kernel-level privileges.
Business impact
The ability for a local user to execute arbitrary code with kernel-level privileges poses a severe risk to organizational security, as it allows attackers to bypass all operating system security controls. This can lead to total system compromise, data theft, and the installation of persistent rootkits, creating significant risk for business continuity and regulatory compliance. The CVSS score of 8.8 reflects the high potential for total system takeover.
Remediation
Immediate Action: Update WibuKey for Windows to version 6.71 or later immediately as specified in the official Wibu-Systems security advisory.
Proactive Monitoring: Monitor system logs for unusual kernel driver activity or unauthorized attempts to load unsigned drivers.
Compensating Controls: Restrict local access to systems running the WibuKey driver to authorized personnel only to minimize the risk of a malicious actor gaining the necessary local access to trigger the exploit.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant security risk due to the potential for kernel-level code execution. Administrators should prioritize the deployment of the vendor-provided patch to all affected Windows systems. Failure to address this flaw could allow local attackers to gain complete control over the underlying infrastructure.
More Wibu-Systems CVEs
Sources
Originally found and disclosed by 김명규 working with Trend Micro Zero Day Initiative, per the CVE Program record.