CVE-2026-81579CWE-123

CVE-2026-81579

High · published August 27, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
5.0
In the wild
Unconfirmed
What it is

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00156 · 5.0th percentile
Weakness
CWE-123 · Write-what-where Condition
Published
2026-08-27T14:16Z
References (1)
EPSS history
Timeline
  • 28 AUG 06:54Z
    EPSS moved — → 0%
    epss
  • 27 AUG 07:42Z
    An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivileged user on Windows
    cvelistv5