Executive brief
Rockwell Automation Arena Simulation is a software tool used by businesses to model and optimize complex industrial systems. A security flaw in its linker component could allow an attacker to take control of a user's computer if the user is tricked into opening a specially crafted malicious file. This could lead to unauthorized access to sensitive data or disruption of business operations.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the linker.exe (Siman) component of Rockwell Automation Arena Simulation. The issue is caused by improper validation of user-supplied data when processing files. An attacker can exploit this by convincing a local user to open a malicious file, leading to memory corruption. Successful exploitation allows for arbitrary code execution within the context of the current process. The vulnerability is addressed in version V17.00.01.
Affected products
- Rockwell Automation Arena Simulation V17.00.00 and prior
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory
- 2026-07-14: patched