Local privilege escalation to SYSTEM in Rockwell Automation FactoryTalk Activation Manager
AI analysis
CVE-2026-16675 is a local privilege escalation flaw in Rockwell Automation FactoryTalk Activation Manager caused by custom installer actions that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker holding ordinary Windows credentials on the host can hijack one of these console windows to obtain a SYSTEM-level command prompt, gaining full access to all files, processes, and system resources. Exposure is limited to Windows machines where the Activation Manager installer is run or repaired while an untrusted credentialed user is logged on locally. There is no evidence of exploitation so far: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.1% probability of exploitation in the next 30 days (1st percentile). The issue was assigned by Rockwell Automation's PSIRT and carries a CVSS 4.0 score of 8.5 (High) with local attack vector and low privileges required.
What to do: Avoid running the FactoryTalk Activation Manager installer or repair operation while untrusted users are logged on to the machine, and restrict local interactive logon rights on hosts where it is installed. Check the Rockwell Automation PSIRT advisory for the affected/fixed version list and upgrade to the fixed release when available. Review which users hold local Windows credentials on engineering workstations and servers hosting Rockwell licensing tools, since the attack requires an authenticated local account.
Affected
| Rockwell Automation FactoryTalk Activation Manager | — |
Estimated exposure
largeon the order of 100,000+ installations (engineering workstations and servers running Rockwell licensing software) — FactoryTalk Activation Manager is the standard licensing/activation component required across Rockwell Automation's FactoryTalk and Studio 5000 software line, which is deployed on engineering workstations and servers at a large share of…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.