C
月内に
Rockwell AutomationのFactoryTalk Activation Manager V5.02およびそれ以前のバージョンに、権限昇格の脆弱性(…
📌 一言でいうと
Rockwell AutomationのFactoryTalk Activation Manager V5.02およびそれ以前のバージョンに、権限昇格の脆弱性(CVE-2026-16675)が確認されました。インストーラーのカスタムアクションにより、SYSTEM権限で動作するコンソールウィンドウが表示されるため、認証済みの攻撃者がこれをハイジャックしてシステム全権限を取得できる可能性があります。影響を受ける環境では、速やかなアップデートが推奨されます。
🔍該当判定
- Rockwell Automation社の「FactoryTalk Activation Manager」をインストールしている
- FactoryTalk Activation Managerのバージョンが V5.02 以前である
- 工場や製造ラインの制御PCで、上記ソフトのインストールや修復作業を行う予定がある
上記いずれにも該当しない → 静観でOK
✅該当時の対応
影響を受けるバージョンのFactoryTalk Activation Managerを最新バージョンにアップデートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Rockwell Automation FactoryTalk Activation Manager CVE-2026-16675 対応について
お疲れさまです。FactoryTalk Activation Managerの脆弱性に関する情報共有です。
■ 概要
FactoryTalk Activation Managerにおいて、権限昇格の脆弱性(CVE-2026-16675)が報告されました。CVSS v3 スコアは 7.8 です。インストーラー実行時にSYSTEM権限で動作するコンソールウィンドウが表示されるため、認証済みユーザーがこれを悪用してSYSTEM権限のコマンドプロンプトを取得し、システムリソースへのフルアクセスを得る可能性があります。
■ 影響範囲
- FactoryTalk Activation Manager V5.02 およびそれ以前のバージョン
■ 対応手順
1. 自社環境における当該製品のバージョンを確認してください。
2. 影響を受けるバージョンを使用している場合は、ベンダーが提供する最新の修正済みバージョンへアップデートを適用してください。
■ 参考情報
- CISA ICS Advisory ICSA-26-244-04
対応優先度: 高
対応期限: 速やかに
お疲れさまです。FactoryTalk Activation Managerの脆弱性に関する情報共有です。
■ 概要
FactoryTalk Activation Managerにおいて、権限昇格の脆弱性(CVE-2026-16675)が報告されました。CVSS v3 スコアは 7.8 です。インストーラー実行時にSYSTEM権限で動作するコンソールウィンドウが表示されるため、認証済みユーザーがこれを悪用してSYSTEM権限のコマンドプロンプトを取得し、システムリソースへのフルアクセスを得る可能性があります。
■ 影響範囲
- FactoryTalk Activation Manager V5.02 およびそれ以前のバージョン
■ 対応手順
1. 自社環境における当該製品のバージョンを確認してください。
2. 影響を受けるバージョンを使用している場合は、ベンダーが提供する最新の修正済みバージョンへアップデートを適用してください。
■ 参考情報
- CISA ICS Advisory ICSA-26-244-04
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Rockwell Automation FactoryTalk Activation Manager CVE-2026-16675
Dear IT/Security Team,
We are sharing information regarding a privilege escalation vulnerability in Rockwell Automation FactoryTalk Activation Manager.
■ Overview
CVE-2026-16675 is a privilege escalation vulnerability with a CVSS v3 score of 7.8. The vulnerability stems from custom installer actions that spawn console windows running with SYSTEM privileges. An authenticated attacker with Windows credentials could hijack these windows to obtain a SYSTEM-level command prompt, granting full access to all files and system resources.
■ Affected Scope
- FactoryTalk Activation Manager V5.02 and below
■ Mitigation Steps
1. Identify all instances of FactoryTalk Activation Manager in the environment and check the version.
2. Update affected installations to the latest patched version provided by the vendor.
■ Reference
- CISA ICS Advisory ICSA-26-244-04
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a privilege escalation vulnerability in Rockwell Automation FactoryTalk Activation Manager.
■ Overview
CVE-2026-16675 is a privilege escalation vulnerability with a CVSS v3 score of 7.8. The vulnerability stems from custom installer actions that spawn console windows running with SYSTEM privileges. An authenticated attacker with Windows credentials could hijack these windows to obtain a SYSTEM-level command prompt, granting full access to all files and system resources.
■ Affected Scope
- FactoryTalk Activation Manager V5.02 and below
■ Mitigation Steps
1. Identify all instances of FactoryTalk Activation Manager in the environment and check the version.
2. Update affected installations to the latest patched version provided by the vendor.
■ Reference
- CISA ICS Advisory ICSA-26-244-04
Priority: High
Deadline: Immediate