First published: Wed Nov 26 2014(Updated: )
Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe, which allows local users to gain privileges via a Trojan horse file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wibu CodeMeter | <=5.10c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8419 is considered a high severity vulnerability due to its ability to allow local users to elevate privileges.
To fix CVE-2014-8419, update the Wibu CodeMeter Runtime to version 5.20 or later which addresses the weak permission issue.
CVE-2014-8419 affects Wibu-Systems CodeMeter Runtime versions up to and including 5.10c.
Local users can exploit CVE-2014-8419 by creating a Trojan horse file to gain unauthorized privileges.
Yes, CVE-2014-8419 is related to insecure file permissions that allow all users read and write access to codemeter.exe.