30 September 2026
KLCERT-25-153: Rockwell Automation FactoryTalk Activation Manager. Privilege escalation
Vendor
-
CVE
-
KLCERT
KLCERT-25-153
Timeline
Timeline
-
Kaspersky ICS CERT advisory published
30 September 2026
-
Advisory published
01 September 2026
-
Vendor Informing
19 November 2025
Description
A local, low-privileged attacker with an interactive session could initiate the repair of affected software versions via an MSI file located in C:\Windows\Installer. Several processes will then be run with NT AUTHORITY\SYSTEM privileges during the repair. Some of these processes will spawn a visible console host window that can be hijacked by an attacker. It is then possible, via certain context menus, to launch a web browser and a subsequent command prompt that will inherit the elevated privileges of the hijacked process.
CVSS v3.1
Exploitability
Local
Attack complexity
Privilege required
User interaction
Confidentiality
Attack conditions
Exploitation requires the use of a web browser, though the latest versions of the built-in Internet Explorer and Microsoft Edge browsers prevent this. A third-party web browser (such as Mozilla Firefox or Google Chrome), installed system-wide, is necessary to exploit the vulnerability.
Integrity
High
Availability
High
Affected products
Rockwell Automation FactoryTalk Activation Manager, all versions prior to V5.03
Mitigation
Vendor mitigation
- Update to FactoryTalk Activation Manager V5.03 or later.
- Customers using the affected software who cannot upgrade to a corrected version should follow security best practices.
Kaspersky ICS CERT mitigation
- Customers using the affected software who cannot upgrade to a corrected version should install the Microsoft patch to address the MSI issue.
- Utilize Microsoft AppLocker to ensure that only administrators can launch MSI operations with installers located in C:\Windows\Installer.
- If possible, avoid using third-party web browsers (except for the latest versions of Internet Explorer or Microsoft Edge) that are installed system-wide.
Timeline
-
Kaspersky ICS CERT advisory published
30 September 2026
-
Advisory published
01 September 2026
-
Vendor Informing
19 November 2025