CVE-2021-41057 is a vulnerability in WIBU CodeMeter Runtime versions prior to 7.30a, affecting products from Microsoft, Siemens, and WIBU. An authenticated local attacker can create a specially crafted symbolic link to overwrite arbitrary files, bypassing permission checks. This vulnerability has a CVSS score of 7.1 (High), indicating high impact on integrity and availability with low attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.30aCPE matchmatch criteria | cpe:2.3:a:wibu:codemeter_runtime:*:*:*:*:*:*:*:* | ||
14CPE matchmatch criteria | cpe:2.3:a:siemens:pss_cape:14:*:*:*:*:*:*:* | ||
>= 34.0.0, < 34.9.1CPE matchmatch criteria | cpe:2.3:a:siemens:pss_e:*:*:*:*:*:*:*:* | ||
>= 35.0.0, < 35.3.2CPE matchmatch criteria | cpe:2.3:a:siemens:pss_e:*:*:*:*:*:*:*:* | ||
< 12.2.6.1CPE matchmatch criteria | cpe:2.3:a:siemens:pss_odms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.