CVE-2017-5176: High severity rockwell automation connected components workbench vulnerability

Published May 19, 2017
·
Updated

A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and 9328-CCWDEVPTE; and Connected Components Workbench - Free Standard Edition (All Supported Languages), v9.01.00 and earlier. Certain DLLs included with versions of CCW software can be potentially hijacked to allow an attacker to gain rights to a victim's affected personal computer. Such access rights can be at the same or potentially higher level of privileges as the compromised user account, including and up to computer administrator privileges.

Affected Software

9 affected components
rockwellautomation Connected Components Workbench<=9.01.00
rockwellautomation 9328-ccwdevdee
rockwellautomation 9328-ccwdevene
rockwellautomation 9328-ccwdevese
rockwellautomation 9328-ccwdevfre
rockwellautomation 9328-ccwdevite
rockwellautomation 9328-ccwdevpte
rockwellautomation 9328-ccwdevzhe
rockwellautomation Connected Components Workbench<=9.01.00

Event History

May 19, 2017
CVE Published
via MITRE·02:43 AM
Data Sourced
via MITRE·02:43 AM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2017-5176?

CVE-2017-5176 is classified as a high-severity vulnerability due to the potential for DLL hijacking.

2

How do I fix CVE-2017-5176?

To fix CVE-2017-5176, you should upgrade to Connected Components Workbench version 9.02.00 or later.

3

What software is affected by CVE-2017-5176?

CVE-2017-5176 affects the Rockwell Automation Connected Components Workbench Developer Edition up to version 9.01.00.

4

What type of vulnerability is CVE-2017-5176?

CVE-2017-5176 is a DLL hijack vulnerability that can allow an attacker to execute arbitrary code.

5

Who is impacted by CVE-2017-5176?

Users of Rockwell Automation Connected Components Workbench versions 9.01.00 and earlier are impacted by CVE-2017-5176.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203