CVE-2026-81581
8.8Wibu-Systems AG · WibuKey
A memory boundary validation error in WibuKey64.sys allows local attackers with low privileges to potentially achieve remote code execution, privilege escalation, or denial of service.
Executive summary
A high-severity memory corruption vulnerability in the WibuKey driver for Windows, identified as CVE-2026-81581, poses a significant risk of system-wide compromise due to the driver operating with kernel-level system privileges.
Vulnerability
This vulnerability involves improper restriction of operations within the bounds of a memory buffer (CWE-119) in the WibuKey64.sys driver. A locally authenticated attacker with low privileges can trigger this flaw by manipulating memory pointers, which may lead to arbitrary code execution at the system level.
Business impact
Successful exploitation of this vulnerability permits an attacker to gain full control over the affected Windows host, as the vulnerable driver runs with system-level privileges. This presents a critical risk of data theft, unauthorized persistent access, and complete system instability. With a CVSS score of 8.8, this flaw represents a high-priority threat that demands prompt remediation to prevent potential lateral movement within the network.
Remediation
Immediate Action: Update the WibuKey software to version 6.71 or later as specified in the official Wibu-Systems security advisory.
Proactive Monitoring: Monitor system logs for unauthorized attempts to interact with the WibuKey64.sys driver or unexpected service crashes associated with the WibuKey process.
Compensating Controls: Restrict local user permissions on systems where the WibuKey driver is installed to minimize the number of accounts capable of interacting with the kernel-mode driver.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for privilege escalation and remote code execution, this vulnerability should be treated with high urgency. Administrators must prioritize updating the WibuKey driver across all affected Windows environments to the patched version. If an immediate update is not feasible, restrict access to the affected systems to trusted users only to mitigate the risk of local exploitation.
More Wibu-Systems AG CVEs
Sources
Originally found and disclosed by KEUM SUNG from Team_F1_Driver, per the CVE Program record.