CVE-2025-9068: Rockwell Automation FactoryTalk® Linx Privilege Escalation Vulnerabilities
A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9068?
CVE-2025-9068 is a high-severity vulnerability due to its potential for exploitation by authenticated attackers.
How do I fix CVE-2025-9068?
To fix CVE-2025-9068, ensure you update the Rockwell Automation Driver Package to the latest version provided by the vendor.
Who is affected by CVE-2025-9068?
CVE-2025-9068 affects users of the Rockwell Automation FactoryTalk Linx software with valid Windows User credentials.
What is the main risk posed by CVE-2025-9068?
The main risk posed by CVE-2025-9068 is that authenticated attackers can hijack console windows to execute unauthorized actions.
Is there an exploit available for CVE-2025-9068?
Yes, CVE-2025-9068 can be exploited by attackers who manage to leverage valid user credentials on affected systems.