Vulnerability Intelligence Report
An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivileged user on Windows
CVE-2026-81579
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.
No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.1
Impact Score:6.1
EPSS Probability:0.16%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-123 ↗CWE-123 Write-what-where condition
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| wibu-systems-ag | wibukey | 0 < 6.71 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.156%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | WIBU-SYSTEMS AG · Vendor · Germany |
| Reserved | 2026-08-27T07:34:49 |
| Published | 2026-08-27T07:42:28 |
| Patch Date | 2025-11-12 |
| Last Updated | 2026-08-28T03:55:30 |
Community Chatter & Buzz