IM
IronMonkey Threat Research
‹ Back to ICS Advisories

ABB Protection and Control IED Manager PCM600 Scheduler Service Privilege Escalation Vulnerability

MEDIUM
CVSS 6.4
Date 2026-09-28T00:30:00+00:00
Source abb-psirt
Published by ABB PSIRT

// Description

ABB is aware of a reported vulnerability in ABB Protection and Control IED Manager (PCM600). A local authenticated user belonging to the PCM600 user group may be able to modify the configuration of a Windows service running with SYSTEM privileges. Successful exploitation could allow an attacker to execute arbitrary commands with elevated privileges on the affected workstation. Note: This document references the ABBPCMSchedulerService_v214 component as implemented in PCM600 version 2.14. However, the described issue is not version-specific and applies equally to the corresponding component in other supported versions of PCM600.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-15952 6.4 medium
CVE-2026-15952. A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host.

// Remediations (1)

Workaround: ABB recommends the following workaround. Although this workaround does not correct the underlying vu
ABB recommends the following workaround. Although this workaround does not correct the underlying vulnerability, it reduces the risk of privilege escalation. Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600. - Open Services.msc. - Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version. - Open Properties and select the Log On tab. - The service should be configured to log on with the same Windows user account that is used for the PCM600 application. - Ensure that this account has the required "Log on as a service" privilege. When authentication is enabled for the IED, the Scheduler tool must be used with the same Windows account configured as the Scheduler Service logon account. For installations using IED security certificates, the PCM600 setting Always trust IED security certificates must be enabled only when PCM600-to-IED communication takes place in a secure and trusted environment. Impact of Workaround -Scheduler functionality will operate using the privileges of the configured Windows user account rather than SYSTEM privileges. - Users may need to be granted the "Log on as a service" Windows user right. - In environments using IED security certificates, enabling Always trust IED security certificates may reduce certificate validation protections and should only be used in secure and trusted environments. - Administrative effort may be required to maintain consistent user accounts between PCM600 and the Scheduler Service.

// References