---
id: CVE-2025-47809
title: >-
  Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately
  after installation (before a logoff or reboot)
summary: >-
  Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately
  after installation (before a logoff or reboot). For exploitation, there must
  have been an unprivileged installation with UAC, and the CodeMeter Control
  Center …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-272
vendor: Wibu
product: CodeMeter
affected:
  - CodeMeter < 8.30a
published: '2025-05-16'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T09:17:37.580'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-47809'
references:
  - url: 'https://www.wibu.com/support/security-advisories/wibu-100120.html'
    label: cve@mitre.org
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-201595.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-331739.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-05-16T13:35:54.604112Z'
epss: 0.00171
epssPercentile: 0.06859
ingestedAt: '2026-09-08T09:30:06.623Z'
---

## Overview

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
