Impact
A privilege escalation flaw occurs when the FactoryTalk® Activation Manager installer creates visible console windows that run with SYSTEM privileges during installation or repair. An authenticated Windows user can hijack one of these console windows and obtain a SYSTEM‑level command prompt, which grants unrestricted access to the file system, processes, and all other system resources.
Affected Systems
The vulnerability affects Rockwell Automation FactoryTalk® Activation Manager version 5.02 and all earlier releases. Affected installations are identified by the CPE string cpe:2.3:a:rockwell_automation:factorytalk_activation_manager:version_5.02_and_below. The vendor recommends upgrading to version 5.03 or later to remediate the issue.
Risk and Exploitability
The flaw has a CVSS score of 8.5, indicating a high severity vulnerability. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Exploitation requires that the attacker is authenticated on a Windows machine that runs the vulnerable installer. The attack path involves the installer’s custom actions spawning console windows with SYSTEM privileges; the attacker then hijacks the window to spawn a privileged command shell. Given the high impact of full system compromise, the risk remains substantial.
OpenCVE Enrichment