PatchSiren cyber security CVE debrief
CVE-2026-81579 wibu-systems-ag CVE debrief
The WibuKey for Windows before version 6.71 is vulnerable due to an untrusted pointer dereference in the WibuKey2_64.sys kernel driver. This allows for local privilege escalation, enabling an attacker to execute arbitrary code, run an administrator shell, or gain full control over the system. System administrators and security teams should review and apply the vendor-provided patch or upgrade to version 6.71 or later. The vulnerability's impact is significant in environments where local privilege escalation could lead to system compromise.
- Vendor
- wibu-systems-ag
- Product
- wibukey
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-27
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-08-27
- Advisory updated
- 2026-09-03
Who should care
System administrators and security teams responsible for managing WibuKey for Windows installations, particularly in environments where local privilege escalation could have significant impacts, should prioritize patching or upgrading to version 6.71 or later. This includes teams managing systems in high-security environments, critical infrastructure, or where unauthorized access could lead to severe consequences. Additionally, IT personnel overseeing software updates and vulnerability management should ensure timely remediation of this vulnerability to prevent potential system compromise and data breaches.
Technical summary
The WibuKey2_64.sys kernel driver in WibuKey for Windows before version 6.71 is vulnerable to an untrusted pointer dereference. This allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. The vulnerability can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system. Immediate attention is required to prevent potential exploitation. The affected product is WibuKey for Windows, and the vulnerability is specific to the kernel driver component.
Defensive priority
This vulnerability allows local privilege escalation via an untrusted pointer dereference in the WibuKey2_64.sys kernel driver. Immediate attention is required to prevent potential exploitation.
Recommended defensive actions
- Apply the vendor-provided patch or upgrade to version 6.71 or later of WibuKey for Windows.
- Restrict access to the WibuKey2_64.sys kernel driver to only necessary users and processes.
- Monitor system logs for suspicious activity related to the WibuKey driver.
- Consider implementing additional security controls, such as driver signing and verification.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE description indicates an untrusted pointer dereference in WibuKey for Windows before version 6.71, allowing a write-what-where primitive for local privilege escalation. Limited details are available from the CVE Program and NVD.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81579 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81579
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81579 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81579
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-100031.pdf
2fc02b1f-71e7-4514-a878-169626f68903
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.