漏洞情报聚合

CVE-2026-81574 - In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggerin - 漏洞详情

漏洞编号:CVE-2026-81574

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-81574

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-134

发布/更新时间:2026-08-27 / 2026-08-27

漏洞描述

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format
specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory
and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and
remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this
vulnerability.

相关链接

相关漏洞

« 返回首页