VYPR

WibuKey

by Wibu

CVEs (8)

  • CVE-2018-3991CriFeb 5, 2019
    risk 0.68cvss 10.0epss 0.34

    An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, version 6.40.2402.500. A specially crafted TCP packet can cause a heap overflow, potentially leading to remote code execution. An attacker can send a malformed…

  • CVE-2018-3990CriFeb 5, 2019
    risk 0.61cvss 9.3epss 0.01

    An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400). A specially crafted IRP request can cause a buffer overflow, resulting in kernel memory corruption and, potentially, privilege…

  • CVE-2026-81581HigAug 27, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits…

  • CVE-2026-81579HigAug 27, 2026
    risk 0.57cvss 8.8epss 0.00

    In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code,…

  • CVE-2021-47810HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    WibuKey Runtime 6.51 contains an unquoted service path vulnerability in the WkSvW32.exe service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\PROGRAM FILES (X86)\WIBUKEY\SERVER\WkSvW32.exe' to inject malicious…

  • CVE-2024-45181HigSep 12, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70. An improper bounds check allows crafted packets to cause an arbitrary address write, resulting in kernel memory corruption.

  • CVE-2024-45182MedSep 12, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary address read, resulting in Denial of Service.

  • CVE-2018-3989MedFeb 5, 2019
    risk 0.28cvss 4.3epss 0.01

    An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400).A specially crafted IRP request can cause the driver to return uninitialized memory, resulting in kernel memory…