nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-7973 CVE-2025-7973
HIGH
Rockwell Automation FactoryTalk® ViewPoint Privilege Escalation Vulnerability
Record summary
CVE-2025-7973 has a selected CVSS score of 8.5 (high).
Description
A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations. During a repair, attackers can hijack the cscript.exe console window, which runs with SYSTEM privileges. This can be exploited to spawn an elevated command prompt, enabling full privilege escalation.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 14, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FactoryTalk® ViewPointBrowse Rockwell Automation / FactoryTalk® ViewPointDefault status: unaffected | CVE List | Version 14.00 or below | affected |
References
2rockwellautomation.com
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1738.html