Local Code Execution Vulnerability in Windows by Rockwell Automation
CVE-2025-24479
8.6HIGH
Key Information:
- Vendor
- Rockwell Automation
- Vendor
- CVE Published:
- 28 January 2025
Summary
A Local Code Execution vulnerability exists in Windows products due to a default setting, potentially allowing attackers to gain elevated access to the Command Prompt. This vulnerability compromises system integrity and opens up avenues for unauthorized operations, making it critical for users to apply the necessary patches and mitigate risks as outlined by Rockwell Automation in their advisory.
Affected Version(s)
FactoryTalk View Machine Edition <V15
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved