CODESYS Development System Incorrect Default Permissions Leading to Local Privilege Escalation

Vulnerability

A vulnerability exists in the CODESYS Development System prior to version 3.5.22.20, where the PackageManager and IPM create temporary directories with insecure default permissions during administrative installation. This flaw allows low-privileged local attackers to modify a temporary bootstrap file, forcing the deployment of arbitrary components, or to exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition by replacing digitally verified installation files with malicious ones before installation. Both issues bypass intended security boundaries during package or add-on installation.

Impact

Exploitation of this vulnerability allows low-privileged local users to escalate privileges, with any installed components being applied in an administrative context. This could lead to the installation of malicious files that compromise the underlying operating system.

Remediation

Users are advised to update the CODESYS Development System to version 3.5.22.20. The update can be downloaded via the CODESYS Installer, from the CODESYS Store, or by visiting the CODESYS Update area for further instructions.

Added: May 26, 2026, 5:19 PM
Updated: May 26, 2026, 5:19 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
10.0
exploitability
2.9
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.