VYPR
Unrated severityNVD Advisory· Published Nov 14, 2021· Updated Aug 4, 2024

CVE-2021-41057

CVE-2021-41057

Description

In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A crafted symbolic link in CodeMeter Runtime before 7.30a allows arbitrary file overwrite without permission checks.

Vulnerability

CVE-2021-41057 affects WIBU CodeMeter Runtime versions prior to 7.30a. The vulnerability resides in the handling of the CmDongles symbolic link. An attacker who can create a crafted symbolic link named CmDongles can overwrite an arbitrary file on the system without proper permission checks [1].

Exploitation

An attacker requires the ability to create a symbolic link named CmDongles in the affected directory. No authentication is needed if the attacker has local access or can trick a privileged process into creating it. The sequence involves creating a symbolic link pointing to a target file, then triggering the CodeMeter service to write to it, thereby overwriting the target [1].

Impact

Successful exploitation allows arbitrary file overwrite, potentially leading to privilege escalation, data corruption, or denial of service. The attacker gains the ability to modify critical system files, which can compromise the integrity and availability of the system [1].

Mitigation

WIBU-Systems released CodeMeter Runtime version 7.30a to address this issue. Users should upgrade to version 7.30a or later. No workaround is documented in the available references [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.