PT-2025-41917 · Microsoft+2 · Windows+2

Published

2025-10-14

·

Updated

2025-10-14

·

CVE-2025-9068

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Rockwell Automation Driver Package x64 (affected versions not specified)
Description A security issue exists in the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. An authenticated attacker with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching of a command prompt running with SYSTEM-level privileges, granting full access to all files, processes, and system resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-16041
CVE-2025-9068

Affected Products

Ftlinx
Rockwell Automation Driver Package X64
Windows