IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Rockwell Automation ControlFLASH

HIGH
CVSS 7.3
Date 2026-09-03T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-12663 7.3 high
A security issue exists within ControlFLASH, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.

// Remediations (4)

Mitigation: If the mitigation above cannot be implemented, Rockwell Automation recommends following their securi
If the mitigation above cannot be implemented, Rockwell Automation recommends following their security best practices.
Mitigation: Users of the affected software who are not able to upgrade to one of thecorrected versions should im
Users of the affected software who are not able to upgrade to one of thecorrected versions should implement the following mitigation: To protect the files, do the following steps to remove the Everyone group: 1. Right-click the C:\Program Files (x86)\ControlFLASH\0001 folder, and then select Properties. 2. In the 0001 Properties dialog, select the Security tab, and then select Edit. 3. In the Permissions for 0001 dialog, in Group or user names, select Everyone, and then select Remove. 4. Select OK.
Mitigation: Rockwell Automation has corrected this issue in software version 15.08, and encourages all users to
Rockwell Automation has corrected this issue in software version 15.08, and encourages all users to update to the newest version.
Mitigation: For more information on this issue, see the Rockwell Automation security advisory at: https://www.ro
For more information on this issue, see the Rockwell Automation security advisory at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html

// References