Privilege Escalation Vulnerability in Rockwell Automation ThinManager
CVE-2025-3617
8.5HIGH
Summary
A privilege escalation vulnerability has been identified in Rockwell Automation ThinManager. During startup, certain files in the temporary folder are deleted, causing the Access Control Entry of the directory to inherit permissions from its parent directory. This flaw opens a pathway for a malicious actor to potentially inherit elevated privileges, posing significant security risks for organizations utilizing this software. It is crucial for users of ThinManager to be aware of this issue and apply the recommended security patch to mitigate the risks associated with this vulnerability.
Affected Version(s)
ThinManager® 14.0.0 & 14.0.1
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved