Wibu: Buffer Overflow in CodeMeter Runtime
Description
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Heap buffer overflow in Wibu CodeMeter Runtime network service (≤7.60b) allows unauthenticated remote RCE and full host compromise.
Vulnerability
A heap buffer overflow vulnerability exists in the Wibu CodeMeter Runtime network service in versions up to 7.60b. The flaw resides in the network service component when processing specially crafted network packets. Affected products include those from Trumpf (e.g., CAD/CAM software using TRUMPF License Expert) and Phoenix Contact devices that use CodeMeter Runtime in server mode. Devices using CodeMeter embedded are not affected [1][2].
Exploitation
An unauthenticated, remote attacker can exploit this vulnerability by sending a crafted network request to the CodeMeter Runtime service. No user interaction or prior authentication is required. The attack is network-based and does not require any special privileges [1][2].
Impact
Successful exploitation allows an attacker to achieve remote code execution (RCE) and gain full access to the host system. In server mode, the attacker can fully compromise the server. In non-networked workstation mode, exploitation leads to privilege escalation and full administrative access on the workstation [1][2].
Mitigation
Wibu-Systems has released a fixed version of CodeMeter Runtime; users should update to the latest version. For Trumpf products, a new version of TRUMPF License Expert that fixes this vulnerability is available. Phoenix Contact also recommends updating affected products. As a workaround, Trumpf notes that machines with a correctly installed mGuard hardware firewall cannot be exploited if used as intended [1][2].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=7.60b+ 1 more
- (no CPE)range: <=7.60b
- (no CPE)range: 7.21g
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.