CVE-2025-47809
Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 8.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1059Command and Scripting Interpreterexecution70 % - Impacto secundario
T1548Abuse Elevation Control Mechanismprivilege escalation75 %
Escalada de privilegios local (AV:L, PR:H) sin interacción del usuario tras instalación de CodeMeter. El atacante accede a instancia privilegiada de Windows Explorer para ejecutar comandos con permisos elevados.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-272
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-47809",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-47809",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-05-16T13:35:54.604112Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.2,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.5
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "Wibu",
"product": "CodeMeter",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "8.30a",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"affectedData": [
{
"vendor": "Siemens",
"product": "Desigo CC family V5.0",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "Desigo CC family V5.1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "Desigo CC family V6",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "Desigo CC family V7",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "Desigo CC family V8",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V8.0 QU2",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SENTRON Powermanager V5",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SENTRON Powermanager V6",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SENTRON Powermanager V7",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SENTRON Powermanager V8",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V8.0 QU2",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC PDM Maintenance Station V5.0",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V5.0 SP2",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC WinCC OA V3.18",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V3.18 P032",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC WinCC OA V3.19",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V3.19 P020",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC WinCC OA V3.20",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V3.20 P008",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-05-16T01:15:51.827",
"references": [
{
"url": "https://www.wibu.com/support/security-advisories/wibu-100120.html",
"source": "cve@mitre.org"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-201595.html",
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-331739.html",
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"description": [
{
"lang": "en",
"value": "CWE-272"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer."
},
{
"lang": "es",
"value": "Las versiones anteriores a la versión 8.30a de Wibu CodeMeter a veces permiten la escalada de privilegios inmediatamente después de la instalación (antes de cerrar sesión o reiniciar). Para que esto ocurra, debe haber una instalación sin privilegios con Control de cuentas de usuario (UAC), y el componente CodeMeter Control Center debe estar instalado y no debe haberse reiniciado. En este caso, el usuario local puede acceder desde Importar licencia a una instancia privilegiada del Explorador de Windows."
}
],
"lastModified": "2026-09-08T09:17:37.580",
"sourceIdentifier": "cve@mitre.org"
}