Security Flaw in Microsoft Installer File of FTLinx by Rockwell Automation
CVE-2025-9067

8.5HIGH

Key Information:

Vendor
CVE Published:
14 October 2025

What is CVE-2025-9067?

A vulnerability exists in the Microsoft Installer File (MSI) utilized by FTLinx, where authenticated attackers holding valid Windows credentials can exploit the system. By initiating a repair process, they can hijack the console window, subsequently launching a command prompt with SYSTEM-level access. This exploitation grants attackers full control over the system, enabling access to all files, processes, and system resources.

Affected Version(s)

FactoryTalk Linx 6.40 and prior

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-9067 : Security Flaw in Microsoft Installer File of FTLinx by Rockwell Automation