Analysis Summary
# Vulnerability: Rockwell Automation FactoryTalk Activation Manager Privilege Escalation
## CVE Details
- **CVE ID:** CVE-2024-38014 (Related Microsoft MSI flaw utilized for escalation)
- **CVSS Score:** 7.8 (High)
- **CWE:** CWE-269 (Improper Privilege Management)
## Affected Systems
- **Products:** Rockwell Automation FactoryTalk Activation Manager
- **Versions:** All versions prior to V5.03
- **Configurations:** Systems where local users have the ability to trigger installer operations via the application.
## Vulnerability Description
The vulnerability exists due to the way FactoryTalk Activation Manager handles Windows Installer (MSI) operations. An attacker with local access can leverage a flaw in the installer process (inherited from or related to CVE-2024-38014) to execute arbitrary code with elevated privileges. The application fails to properly restrict installer actions, allowing a low-privileged user to gain SYSTEM-level access by exploiting the trusted installer service.
## Exploitation
- **Status:** Vulnerability confirmed; referenced as an escalation path.
- **Complexity:** Low (requires local access but minimal specialized skill).
- **Attack Vector:** Local (requires the attacker to be logged into the system).
## Impact
- **Confidentiality:** High (Full access to system data).
- **Integrity:** High (Ability to modify system files and configurations).
- **Availability:** High (Ability to disable services or delete critical files).
## Remediation
### Patches
- **Rockwell Automation:** Update FactoryTalk Activation Manager to **V5.03** or later.
- **Microsoft:** Install the OS-level patch for **CVE-2024-38014** to address the underlying MSI handling flaw.
### Workarounds
- **AppLocker Policy:** Utilize Microsoft AppLocker to enforce "Windows Installer Rules," ensuring only administrators can launch MSI operations from the `C:\Windows\Installer` directory.
- **Browser Security:** Avoid using third-party web browsers (excluding current versions of Edge/IE) that are installed system-wide, as they can sometimes be used as a vector to trigger installer behaviors.
- **General Best Practices:** Follow the Rockwell Automation Security Best Practices advisory at hxxps[://]rockwellautomation[.]custhelp[.]com/app/answers/answer_view/a_id/1085012/loc/en_US.
## Detection
- **Indicators of Compromise:** Unusual activity from the Windows Installer service (`msiexec.exe`) initiated by a non-admin user account.
- **Detection Methods:** Monitor for the creation of unexpected scheduled tasks or services following an MSI execution event. Audit logs for event IDs related to privilege escalation and unauthorized group membership changes.
## References
- **Kaspersky ICS CERT Advisory:** hxxps[://]ics-cert[.]kaspersky[.]com/advisories/2026/09/30/rockwell-automation-factorytalk-activation-manager-privilege-escalation/
- **Microsoft Security Advisory:** hxxps[://]msrc[.]microsoft[.]com/update-guide/en-US/advisory/CVE-2024-38014
- **Rockwell Automation Support:** hxxps[://]rockwellautomation[.]custhelp[.]com/