CVE-2025-47809: High severity wibu-systems ag codemeter runtime vulnerability
Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47809?
CVE-2025-47809 has a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2025-47809?
To fix CVE-2025-47809, update Wibu CodeMeter to version 8.30a or later.
Who is affected by CVE-2025-47809?
CVE-2025-47809 affects users of Wibu CodeMeter versions prior to 8.30a who installed it with unprivileged permissions.
What type of vulnerability is CVE-2025-47809?
CVE-2025-47809 is characterized as a privilege escalation vulnerability.
Is a system reboot required to exploit CVE-2025-47809?
No, CVE-2025-47809 can be exploited immediately after installation without requiring a reboot.