Sceawere
Vulnerability Detail
CVE-2026-84854UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WibuKey Driver Buffer Overflow
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7
- Creation Date
- 15h ago
- Vendor
- wibu-systems-ag
- Product
- wibukey
- Attack Type
- CWE-787 Out-of-bounds write
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In the WibuKey driver for Windows below Version 6.72, insufficient validation of user input when calculating the size of a kernel buffer could cause small amounts of data to be written outside the intended kernel buffer. This can lead to a system crash. Under unfavorable circumstances, adjacent kernel memory may be modified.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.0",
"pubDate": "2026-10-06T10:16:54.230Z",
"pubdate": "2026-10-06T10:16:54.230Z",
"executiveSummary": "The WibuKey driver for Windows, in versions prior to 6.72, contains a critical input validation vulnerability.\nThis flaw manifests as an out-of-bounds write resulting from improper calculation of kernel buffer sizes.\nThe vulnerability allows an unprivileged local attacker to trigger a system crash via a Denial of Service (DoS) or, under specific conditions, achieve memory corruption.\nThe impact is significant, as successful exploitation may result in the modification of adjacent kernel memory, potentially leading to unauthorized data manipulation or kernel-level code execution.\nExploitation requires local access to the affected system to interact with the vulnerable driver interface.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient validation of user-supplied input used during the determination of kernel-mode buffer allocation sizes within the WibuKey driver.\nWhen the driver processes specific IOCTLs (Input/Output Control) or system calls, it calculates the required buffer size based on user-provided parameters without enforcing strict bounds checking. This failure to sanitize the input leads to a discrepancy between the allocated memory region and the amount of data written to that buffer.\nThe vulnerability allows for an out-of-bounds write operation, where data is written beyond the memory boundary intended for the driver operation. This primitive is a classic heap or pool-based buffer overflow occurring within the kernel's address space.\nThe attack flow typically involves an attacker crafting a malicious payload that specifies an input size that bypasses the driver's rudimentary checks but results in an integer calculation that forces the allocation of a smaller buffer than the subsequent write operation requires.\nUpon execution, the driver writes the user-controlled data into the undersized buffer, causing an overflow into adjacent kernel memory structures. If the overflow overwrites critical control structures, such as object headers, function pointers, or synchronization primitives, it triggers an immediate system crash or Kernel Panic, causing a Denial of Service.\nIn more complex exploitation scenarios, an attacker may leverage the ability to corrupt adjacent memory to target sensitive kernel objects. If the attacker can reliably control the content and the location of the adjacent memory, they may achieve arbitrary write primitives, which can be leveraged to escalate privileges by overwriting token structures or modifying system state variables to disable security protections.\nThe vulnerability is inherent to the driver's handling of user-mode to kernel-mode communication. As the flaw resides in the driver's logic rather than the network stack, it is not directly reachable over a network without an intermediate local-access mechanism (e.g., a local user account or a secondary exploit chain). However, because the code executes with high privileges (Ring 0), the impact of a successful exploit is comprehensive, affecting the entire system's stability and integrity."
}