Privilege Escalation Vulnerability in Rockwell Automation ThinManager
CVE-2025-3617

8.5HIGH

Key Information:

Vendor
CVE Published:
15 April 2025

Summary

A privilege escalation vulnerability has been identified in Rockwell Automation ThinManager. During startup, certain files in the temporary folder are deleted, causing the Access Control Entry of the directory to inherit permissions from its parent directory. This flaw opens a pathway for a malicious actor to potentially inherit elevated privileges, posing significant security risks for organizations utilizing this software. It is crucial for users of ThinManager to be aware of this issue and apply the recommended security patch to mitigate the risks associated with this vulnerability.

Affected Version(s)

ThinManager® 14.0.0 & 14.0.1

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.