CVE-2014-8419: High severity codemeter runtime vulnerability
Published Nov 26, 2014
·Updated
Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe, which allows local users to gain privileges via a Trojan horse file.
Affected Software
1 affected component
Wibu CodeMeter Runtime<=5.10c
Event History
Nov 26, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8419?
CVE-2014-8419 is considered a high severity vulnerability due to its ability to allow local users to elevate privileges.
2
How do I fix CVE-2014-8419?
To fix CVE-2014-8419, update the Wibu CodeMeter Runtime to version 5.20 or later which addresses the weak permission issue.
3
What systems are affected by CVE-2014-8419?
CVE-2014-8419 affects Wibu-Systems CodeMeter Runtime versions up to and including 5.10c.
4
What action can local users take to exploit CVE-2014-8419?
Local users can exploit CVE-2014-8419 by creating a Trojan horse file to gain unauthorized privileges.
5
Is CVE-2014-8419 related to insecure file permissions?
Yes, CVE-2014-8419 is related to insecure file permissions that allow all users read and write access to codemeter.exe.