30 September 2026

KLCERT-25-153: Rockwell Automation FactoryTalk Activation Manager. Privilege escalation

Researcher

Maxim KorotkovSecurity Researcher, Kaspersky

Timeline

Timeline

  • Kaspersky ICS CERT advisory published

    30 September 2026

  • Advisory published

    01 September 2026

  • Vendor Informing

    19 November 2025

Description

A local, low-privileged attacker with an interactive session could initiate the repair of affected software versions via an MSI file located in C:\Windows\Installer. Several processes will then be run with NT AUTHORITY\SYSTEM privileges during the repair. Some of these processes will spawn a visible console host window that can be hijacked by an attacker. It is then possible, via certain context menus, to launch a web browser and a subsequent command prompt that will inherit the elevated privileges of the hijacked process.


Exploitability

Local

Attack complexity

Low

Privilege required

Low

User interaction

None

Confidentiality

High

Attack conditions

Exploitation requires the use of a web browser, though the latest versions of the built-in Internet Explorer and Microsoft Edge browsers prevent this. A third-party web browser (such as Mozilla Firefox or Google Chrome), installed system-wide, is necessary to exploit the vulnerability.

Integrity

High

Availability

High

Affected products

Rockwell Automation FactoryTalk Activation Manager, all versions prior to V5.03

Mitigation

Vendor mitigation

  • Update to FactoryTalk Activation Manager V5.03 or later.
  • Customers using the affected software who cannot upgrade to a corrected version should follow security best practices.

Kaspersky ICS CERT mitigation

  • Customers using the affected software who cannot upgrade to a corrected version should install the Microsoft patch to address the MSI issue.
  • Utilize Microsoft AppLocker to ensure that only administrators can launch MSI operations with installers located in C:\Windows\Installer.
  • If possible, avoid using third-party web browsers (except for the latest versions of Internet Explorer or Microsoft Edge) that are installed system-wide.

Timeline

  • Kaspersky ICS CERT advisory published

    30 September 2026

  • Advisory published

    01 September 2026

  • Vendor Informing

    19 November 2025