Important Security Notification - License Dongle (WibuKey) Runtime v6.60 or older

Be first to know new releases, updates and features from GC Image
geschd23
Posts: 15
Joined: June 11th, 2018, 1:07 pm

Important Security Notification - License Dongle (WibuKey) Runtime v6.60 or older

Post by geschd23 »

Wibu-Systems has notified us about the presence of two vulnerabilities in WibuKey. Our software use WibuKey as license dongles. More information can be found here: https://cdn.wibu.com/fileadmin/wibu_dow ... -94453.pdf

Wibu-Systems has released an update (v6.70) of WibuKey runtime:
https://www.wibu.com/support/user/downl ... _for_Users

, and recommends an update of WibuKey runtime to a new updated version on all systems not running in protected environments.

Our current recommendation:

We recommend all users to check if WibuKey runtime v6.60 or older is installed on their systems ASAP. If yes,
  1. Unplug any WibuKey dongle
  2. Uninstall the WibuKey runtime. Choose Ignore if a file is reported locked and continue to uninstall.
  3. Restart
  4. Download and run the latest WibuKey runtime v6.70 installer
  5. Uncheck both server and network options as shown below if the WibuKey is used only for GC Image or LC Image software, and then install. If the WibuKey is used by another software, contact the software vendor for instructions.
Image
geschd23
Posts: 15
Joined: June 11th, 2018, 1:07 pm

Re: Important Security Notification - License Dongle (WibuKey) Runtime v6.60 or older

Post by geschd23 »

Our initial assessment:
  • Product Affected:
    WibuKey dongles are used by GC Image software suites for licensing protection. All versions of GC Image software installers have a WibuKey Runtime installer bundled. The bundled WibuKey runtime installer is v6.60 or older, and invoked by default.
  • System Affected:
    Any system where any edition and version of GC Image software has been installed, may have the WibuKey runtime installed and is potentially affected.
  • Vulnerability Details
    The following two vulnerabilities were publicly disclosed on Sept 11th, 2024.
    • CVE-2024-45181: An improper buffer bounds check in WibuKey32.sys and WibuKey64.sys allows specially crafted calls
      to cause arbitrary address writes, resulting in kernel memory corruption.
    • CVE-2024-45182: An improper buffer bounds check in WibuKey32.sys and WibuKey64.sys allows specially crafted calls
      to cause an arbitrary address read, which could result in denial of service.
      Local access is needed for exploitation. The vulnerabilities cannot be exploited via the network.
  • Mitigation:
    As local access is needed to exploit the vulnerabilities, it is recommended to take strict measures to control the access to the systems where the vulnerable WibuKey driver is installed.
    To resolve these vulnerabilities, update the WibuKey runtime, or remove the WibuKey runtime, as described in our recommendation above.

    Installers for GC Image software suites with the updated version 6.70 of the WibuKey Runtime software will be provided online soon starting from the latest versions. For replacing CD or DVD media, please contact us.
geschd23
Posts: 15
Joined: June 11th, 2018, 1:07 pm

Re: Important Security Notification - License Dongle (WibuKey) Runtime v6.60 or older

Post by geschd23 »

Download Status:
  • (Sept 30th 2024 5:15pm US Central Time) Installers for current version (v2024r2) online have been updated to include WibuKey runtime v6.70. The updated installers are indicated by "sp1" (security patch 1) in the installer exe filename.
  • Update and maintenance packages do not contain WibuKey runtime.
  • Installers for previous versions (v2024r1 or older) have not been updated, and still contain an old version of WibuKey runtime.
When installing an old version or installing with an old installer, be sure to uncheck and skip the WibuKey installation option at the end of the setup, then follow our recommendation to download and install the latest WibuKey Runtime v6.70.
geschd23
Posts: 15
Joined: June 11th, 2018, 1:07 pm

Re: Important Security Notification - License Dongle (WibuKey) Runtime v6.60 or older

Post by geschd23 »

To verify you are running the correct version (6.70) of the WibuKey driver:
  • Open Windows' Control Panel > Search "WibuKey"
  • Open WibuKey Configuration.
  • Click the About tab > check for the 6.70 version number
Image