Junglewise Threat Intelligence

CVE-2026-61389: AutomationDirect Productivity Suite out-of-bounds write via IOCTL

CVE-2026-61389 · Severity: high · CVSS 7 · Published 2026-07-16

Technologies: AutomationDirect Productivity Suite. Vendors: AutomationDirect.

Executive brief

AutomationDirect Productivity Suite is a software package used to program and manage industrial control systems. A vulnerability in this suite allows a local user to corrupt system memory, which could lead to an unauthorized increase in privileges or cause the entire system to crash. This could disrupt manufacturing operations or allow an attacker to gain deeper control over the engineering workstation.

Technical details

An out-of-bounds write (CWE-787) exists in the AutomationDirect Productivity Suite. The vulnerability is triggered when the software processes a specially crafted I/O Control (IOCTL) request. A local attacker with low privileges can exploit this to cause kernel memory corruption. Successful exploitation can lead to local privilege escalation (LPE) or a denial-of-service (DoS) condition via system instability. The vulnerability is addressed in version v4.7.0.47.

Affected products

  • AutomationDirect Productivity Suite <=v4.6.2.2

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory: ICSA-26-197-04 published by CISA

References

Related threats