### [CVE-2025-7973](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-7973) ![](https://img.shields.io/static/v1?label=Product&message=FactoryTalk%C2%AE%20ViewPoint&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=Version%2014.00%20or%20below%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-268%3A%20Privilege%20Chaining&color=brightgreen) ### Description A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations. During a repair, attackers can hijack the cscript.exe console window, which runs with SYSTEM privileges. This can be exploited to spawn an elevated command prompt, enabling full privilege escalation. ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds