CVE-2025-24479

Published Jan 28, 2025

Last updated 25 days ago

Overview

Description
A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and allows access to the Command Prompt as a higher privileged user.
Source
PSIRT@rockwellautomation.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.6
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

Weaknesses

PSIRT@rockwellautomation.com
CWE-863

Social media

Hype score
Not currently trending
  1. Actively exploited CVE : CVE-2025-24479

    @transilienceai

    6 Feb 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Actively exploited CVE : CVE-2025-24479

    @transilienceai

    5 Feb 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Actively exploited CVE : CVE-2025-24479

    @transilienceai

    4 Feb 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Rockwell Automation FactoryTalk View Machine Edition (ME)に重大(Critical)な脆弱性。CVE-2025-24480はCVSSスコア9.8で、入力無害化の欠如に起因し、攻撃者が遠隔から高権限ユーザでコマンドを実行することが可能なもの。ローカル権限昇格CVE-2025-24479と併せて修正。 https://t.co/ryz0w6Cnvv

    @__kokumoto

    2 Feb 2025

    527 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-24480 (CVSS 9.8): Rockwell Automation Addresses Critical Flaw in FactoryTalk View ME CVE-2025-24479 and CVE-2025-24480 could potentially allow attackers to execute malicious code and compromise affected systems https://t.co/9pLxtk4OTS

    @the_yellow_fall

    1 Feb 2025

    398 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-24479 A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and allows access to the… https://t.co/oPrqyIbgL1

    @CVEnew

    28 Jan 2025

    194 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2025-24479: HIGH] Product version is affected by a Local Code Execution Vulnerability due to a default setting in Windows. Exploit could provide elevated Command Prompt access. Cybersecurity alert!#cybersecurity,#vulnerability https://t.co/pfPSFcc3e6 https://t.co/kcL7Eka25p

    @CveFindCom

    28 Jan 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes