CVE-2020-37017
Wibu-Systems CodeMeter vulnerability analysis and mitigation

Overview

CVE-2020-37017 is an unquoted service path vulnerability in Wibu-Systems CodeMeter version 6.60 that allows local users with low privileges to potentially execute arbitrary code with elevated (LocalSystem) privileges. The vulnerability was formally published on January 29, 2026, and is assigned by VulnCheck. It affects the CodeMeter Runtime Server service on Windows systems. The CVSS v3.1 base score is 7.8 (High), and the CVSS v4.0 base score is 8.5 (High) (VulnCheck Advisory, Feedly).

Technical details

The root cause is classified as CWE-428 (Unquoted Search Path or Element). When the CodeMeter Runtime Server service is configured with an unquoted binary path containing spaces, Windows' service control manager may resolve the path ambiguously, allowing an attacker to place a malicious executable in a directory that is evaluated before the legitimate binary. Exploitation requires local access and low-level privileges — no user interaction is needed. A public proof-of-concept exploit is available on Exploit-DB (EDB-ID 48735) (Exploit-DB, VulnCheck Advisory).

Impact

Successful exploitation allows a local attacker to escalate privileges to LocalSystem, the highest privilege level on a Windows host, enabling full control over the affected system. This includes the ability to read, modify, or delete any file, install software, create new accounts, and potentially pivot to other systems on the network. Confidentiality, integrity, and availability are all rated as High impact (VulnCheck Advisory, Feedly).

Exploitability

A public proof-of-concept exploit has been available on Exploit-DB since 2020 (EDB-ID 48735), making this vulnerability accessible to low-skilled attackers with local access. The EPSS score is approximately 0.011% (0.000110), indicating a low probability of active exploitation in the near term. There is no current evidence of in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Exploit-DB, Feedly).

Exploitation steps

  1. Reconnaissance: Identify systems running CodeMeter Runtime Server version 6.60 on Windows. Use sc qc CodeMeter or wmic service get name,pathname,startmode to enumerate service paths and confirm the unquoted path vulnerability.
  2. Identify the unquoted path: Confirm that the CodeMeter service binary path contains spaces and is not enclosed in quotation marks (e.g., C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe).
  3. Determine writable directories: Check write permissions on intermediate directories in the path (e.g., C:\Program.exe or C:\Program Files\CodeMeter.exe) using tools like icacls.
  4. Place malicious executable: Write a crafted executable (e.g., a reverse shell or privilege escalation payload) to the highest-priority ambiguous path that the attacker can write to (e.g., C:\Program.exe).
  5. Trigger service restart: Wait for or trigger a system reboot or service restart. Windows will resolve the unquoted path and execute the malicious binary with LocalSystem privileges, granting the attacker full system control (Exploit-DB, VulnCheck Advisory).

Indicators of compromise

  • File System: Unexpected executables placed in root or intermediate directories matching the unquoted service path pattern (e.g., C:\Program.exe, C:\Program Files\CodeMeter.exe); new or modified files in CodeMeter installation directories.
  • Logs: Windows Event Log entries (Event ID 7045 or 7036) showing unexpected service starts or stops for CodeMeter; Event ID 4688 showing new process creation with SYSTEM privileges spawned from services.exe.
  • Process: Unusual processes running as SYSTEM that are not part of the standard CodeMeter installation; child processes of services.exe that are not CodeMeter.exe.
  • Registry: Changes to the HKLM\SYSTEM\CurrentControlSet\Services\CodeMeter registry key, particularly the ImagePath value (Exploit-DB).

Mitigation and workarounds

The primary remediation is to upgrade CodeMeter Runtime to a version later than 6.60 that corrects the unquoted service path. As an immediate workaround, administrators can manually edit the service registry key (HKLM\SYSTEM\CurrentControlSet\Services\CodeMeter\ImagePath) to enclose the binary path in double quotation marks, eliminating the path ambiguity. Additionally, restrict write permissions on directories in the service path to prevent non-privileged users from placing malicious executables. Consult the Wibu-Systems product page for the latest patched runtime version (Wibu-Systems, VulnCheck Advisory).

Community reactions

Coverage of CVE-2020-37017 has been limited to vulnerability database aggregators and security blogs following its formal NVD publication in January 2026. No significant vendor statements, notable researcher commentary, or major media coverage has been identified beyond standard CVE tracking and the original Exploit-DB submission (ctrlaltnod.com, infinitsec.net).

Additional resources


SourceThis report was generated using AI

Related Wibu-Systems CodeMeter vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-20093CRITICAL9.1
  • Wibu-Systems CodeMeter logoWibu-Systems CodeMeter
  • cpe:2.3:a:wibu:codemeter
NoYesJun 16, 2021
CVE-2020-37017HIGH8.5
  • Wibu-Systems CodeMeter logoWibu-Systems CodeMeter
  • cpe:2.3:a:wibu:codemeter
NoYesJan 29, 2026
CVE-2025-47809HIGH8.2
  • Wibu-Systems CodeMeter logoWibu-Systems CodeMeter
  • cpe:2.3:a:wibu:codemeter
NoYesMay 16, 2025
CVE-2021-20094HIGH7.5
  • Wibu-Systems CodeMeter logoWibu-Systems CodeMeter
  • cpe:2.3:a:wibu:codemeter
NoYesJun 16, 2021
CVE-2020-16233HIGH7.5
  • Wibu-Systems CodeMeter logoWibu-Systems CodeMeter
  • cpe:2.3:a:wibu:codemeter
NoYesSep 16, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management