PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81579 wibu-systems-ag CVE debrief

The WibuKey for Windows before version 6.71 is vulnerable due to an untrusted pointer dereference in the WibuKey2_64.sys kernel driver. This allows for local privilege escalation, enabling an attacker to execute arbitrary code, run an administrator shell, or gain full control over the system. System administrators and security teams should review and apply the vendor-provided patch or upgrade to version 6.71 or later. The vulnerability's impact is significant in environments where local privilege escalation could lead to system compromise.

Vendor
wibu-systems-ag
Product
wibukey
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-27
Original CVE updated
2026-09-03
Advisory published
2026-08-27
Advisory updated
2026-09-03

Who should care

System administrators and security teams responsible for managing WibuKey for Windows installations, particularly in environments where local privilege escalation could have significant impacts, should prioritize patching or upgrading to version 6.71 or later. This includes teams managing systems in high-security environments, critical infrastructure, or where unauthorized access could lead to severe consequences. Additionally, IT personnel overseeing software updates and vulnerability management should ensure timely remediation of this vulnerability to prevent potential system compromise and data breaches.

Technical summary

The WibuKey2_64.sys kernel driver in WibuKey for Windows before version 6.71 is vulnerable to an untrusted pointer dereference. This allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. The vulnerability can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system. Immediate attention is required to prevent potential exploitation. The affected product is WibuKey for Windows, and the vulnerability is specific to the kernel driver component.

Defensive priority

This vulnerability allows local privilege escalation via an untrusted pointer dereference in the WibuKey2_64.sys kernel driver. Immediate attention is required to prevent potential exploitation.

Recommended defensive actions

  • Apply the vendor-provided patch or upgrade to version 6.71 or later of WibuKey for Windows.
  • Restrict access to the WibuKey2_64.sys kernel driver to only necessary users and processes.
  • Monitor system logs for suspicious activity related to the WibuKey driver.
  • Consider implementing additional security controls, such as driver signing and verification.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE description indicates an untrusted pointer dereference in WibuKey for Windows before version 6.71, allowing a write-what-where primitive for local privilege escalation. Limited details are available from the CVE Program and NVD.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81579 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81579

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81579 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81579

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-100031.pdf

    2fc02b1f-71e7-4514-a878-169626f68903

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.