Beveiligingsadvies

CVE-2025-9068

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-10-14 12:23:45
Laatst bijgewerkt 2025-10-14 18:49:27
Toegewezen door Rockwell
CVSS-score 8.5
Status PUBLISHED

Beschrijving

A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.