A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. If exploited, a threat actor could inherit elevated privileges.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Apr 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-276 |
Tue, 15 Apr 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 15 Apr 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. If exploited, a threat actor could inherit elevated privileges. | |
Title | Local Privilege Escalation in ThinManager® | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2025-04-17T17:25:03.386Z
Reserved: 2025-04-14T23:45:31.896Z
Link: CVE-2025-3617

Updated: 2025-04-15T17:40:14.596Z

Status : Awaiting Analysis
Published: 2025-04-15T18:15:53.620
Modified: 2025-04-17T18:15:51.653
Link: CVE-2025-3617

No data.