Security Vulnerability in Rockwell Automation Driver Package MSI Repair Functionality
CVE-2025-9068

8.5HIGH

Key Information:

Vendor
CVE Published:
14 October 2025

What is CVE-2025-9068?

A security issue in the repair functionality of the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) allows authenticated attackers with valid Windows user credentials to exploit the system. By initiating a repair process, an attacker can hijack the resulting console window for vbpinstall.exe. This vulnerability enables the execution of a command prompt with SYSTEM-level privileges, granting full access to all files, processes, and system resources, thereby posing a significant risk to the integrity and security of affected systems.

Affected Version(s)

FactoryTalk Linx 6.40 and prior

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-9068 : Security Vulnerability in Rockwell Automation Driver Package MSI Repair Functionality