CVE-2026-84854
Received Received - Intake

WibuKey Driver Kernel Buffer Overflow

Vulnerability report for CVE-2026-84854, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: 2fc02b1f-71e7-4514-a878-169626f68903

Description

In the WibuKey driver for Windows below Version 6.72, insufficient validation of user input when calculating the size of a kernel buffer could cause small amounts of data to be written outside the intended kernel buffer. This can lead to a system crash. Under unfavorable circumstances, adjacent kernel memory may be modified.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wibu-systems-ag wibukey 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the WibuKey driver for Windows versions below 6.72. It involves insufficient validation of user input when calculating the size of a kernel buffer, which can cause small amounts of data to be written outside the intended buffer. This may lead to a system crash or, in unfavorable conditions, modification of adjacent kernel memory.

Impact Analysis

This vulnerability can cause system crashes or instability due to kernel memory corruption. If adjacent kernel memory is modified, it could potentially lead to privilege escalation or unauthorized access, depending on the affected system's configuration and the attacker's capabilities.

Mitigation Strategies

Update the WibuKey driver for Windows to Version 6.72 or later to address the insufficient validation issue. Avoid using vulnerable versions until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84854. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart