CVE Database
/

CVE-2025-9068

Back to search

CVE-2025-9068

Published: Oct 14, 2025

Modified: Oct 14, 2025

PUBLISHED

Description

A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.

VendorProductVersions

Rockwell Automation

FactoryTalk Linx

affected
6.40 and prior

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now