Back to Intelligence

CVE-2026-15952 & CVE-2026-15953: ABB PCM600 IED Manager Privilege Escalation and Path Traversal Defense Guide

SA
Security Arsenal Team
October 1, 2026
13 min read

CISA has published an ICS advisory for ABB Protection and Control IED Manager PCM600, an engineering tool used to configure and manage protection and control intelligent electronic devices in power environments. The advisory identifies two vulnerabilities in PCM600 versions 2.14 and earlier: CVE-2026-15952 and CVE-2026-15953. Successful exploitation could allow an attacker to escalate privileges or overwrite files. The vendor lists a CVSS v3 base score of 6.4, the affected equipment is deployed worldwide, and the critical infrastructure sector most directly exposed is Energy.

For defenders, this is not a routine workstation patch ticket. PCM600 typically lives on engineering workstations, OT jump hosts, or maintenance laptops that have trusted access to relays, bay controllers, substation automation networks, and configuration files. A medium CVSS score does not mean medium operational risk when the host can alter protection logic or move laterally into a substation environment. Treat this as an exposure-management priority for any organization operating transmission, distribution, generation, or large industrial power systems.

The source advisory does not state confirmed in-the-wild exploitation or CISA KEV inclusion at the time of this writing. That absence should not create comfort. The weakness classes named in the advisory are Incorrect Permission Assignment for Critical Resource and Improper Limitation of a Pathname to a Restricted Directory, commonly path traversal. Both are highly actionable on Windows engineering hosts if an attacker can reach the local scheduler component, plant crafted content, or influence file paths used by the product.

Affected Products, Versions, and Risk Context

Affected product: ABB Protection and Control IED Manager PCM600. Affected versions: PCM600 2.14 and earlier. CVEs named in the advisory: CVE-2026-15952 and CVE-2026-15953. Reported impact: privilege escalation and file overwrite. Sector: Energy. Deployment: Worldwide. Vendor: ABB, headquartered in Switzerland.

CVE-2026-15952 is described as a vulnerability in the Scheduler Service installed with PCM600. The advisory summary is truncated in the provided source, but the mapped weakness, Incorrect Permission Assignment for Critical Resource, strongly suggests that a service object, directory, executable, scheduled task, or service-controlled resource may have permissions that are broader than required. On Windows, the defensive hypothesis is straightforward: a privileged service interacts with resources that a lower-privileged user or process can influence, modify, replace, or coerce into writing outside the intended boundary.

CVE-2026-15953 maps to Improper Limitation of a Pathname to a Restricted Directory, or path traversal. The defensive concern is that PCM600 or the Scheduler Service may accept a path containing traversal sequences, environment-dependent path expansion, symlink or junction influence, or insufficient canonicalization before file creation or overwrite. In an OT engineering workflow, overwritten files could include relay configuration exports, project files, scripts, templates, firmware staging artifacts, logs, or service executables if permissions are weak.

Exploitation requirements will matter. A purely local vulnerability still has real value after phishing, stolen credentials, remote access trojan activity, malicious maintenance media, or compromise of a vendor support account. If the engineering host is reachable from IT through remote administration, file shares, or remote support tooling, local privilege escalation and file overwrite become part of an intrusion path into critical control system configuration workflows.

Technical Analysis for Defenders

The most important defensive point is the trust position of PCM600 hosts. Engineering tools often run with elevated rights because operators must discover devices, write settings, compare configurations, and commission IEDs. That creates three practical attack chains.

First, privilege escalation through the Scheduler Service. If the service executes under a privileged account such as LocalSystem or a domain service account while touching weakly ACLed paths, an attacker may attempt to replace binaries, influence loaded components, abuse scheduled actions, or cause the service to perform a privileged operation on attacker-controlled content. Defenders should verify the service account, binary path, service DACL, directory ACLs, and whether standard users can modify anything in the service execution path.

Second, path traversal into unintended write locations. The attacker goal is to make a trusted process write outside the restricted directory. Observable behaviors include path strings containing ../ or .., process command lines or file operations referencing user-writable staging locations followed by writes to Program Files, Windows, system configuration locations, project repositories, or OT file shares. In substation environments, file overwrite can be worse than code execution because corrupted relay settings or altered comparison reports may look like normal engineering activity.

Third, post-compromise persistence. Once an attacker can overwrite files or execute as a more privileged context, likely next steps include replacing a service binary, planting a scheduled task, modifying an engineering script, or creating an account with local administrative rights. Hunt beyond the CVE itself for child processes spawned from PCM600-related components, unexpected writes by the PCM600 service account, and new persistence created shortly after PCM600 project or scheduler activity.

The advisory does not provide indicators of compromise, exploit code, or confirmed active exploitation in the source text. Detection should therefore focus on durable behaviors tied to the named weakness classes rather than brittle hashes. Prioritize process lineage, file-write destination, service permission drift, and traversal strings in paths.

Detection and Hunting

Use the following rules as high-signal starting points. Scope them to known PCM600 engineering workstations and OT jump hosts first, then expand only if false positives are manageable. Avoid deploying process-name rules globally without an asset inventory; many organizations have only a handful of PCM600 hosts, and focused deployment will outperform broad noisy coverage.

YAML
---
title: PCM600 Scheduler Service Spawning Shell or Script Interpreter
id: 8c3f1b62-5d9a-4c71-b9f4-2a6e7d0c9b11
status: experimental
description: Detects command shells or script interpreters spawned in the context of ABB PCM600 or its Scheduler Service, which may indicate privilege escalation or post-exploitation activity.
references:
  - https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03
author: Security Arsenal
date: 2026/02/03
tags:
  - attack.execution
  - attack.privilege_escalation
  - attack.t1059
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentCommandLine|contains:
      - 'PCM600'
      - 'Scheduler Service'
    ParentImage|contains: 'PCM600'
  selection_child:
    Image|contains:
      - 'cmd.exe'
      - 'powershell.exe'
      - 'pwsh.exe'
      - 'wscript.exe'
      - 'cscript.exe'
      - 'mshta.exe'
      - 'rundll32.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Vendor maintenance scripts or commissioning procedures that legitimately invoke shells from PCM600 workflows
level: high
---
title: Path Traversal Sequence in PCM600 Related Process or File Operation
id: 6e2a8d40-1b77-4f53-9c31-7d5b8f0a2e44
status: experimental
description: Detects traversal sequences associated with PCM600-related process command lines or file events, consistent with pathname restriction bypass attempts.
references:
  - https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03
author: Security Arsenal
date: 2026/02/03
tags:
  - attack.defense_evasion
  - attack.privilege_escalation
  - attack.t1006
logsource:
  product: windows
  category: file_event
detection:
  selection_image:
    Image|contains: 'PCM600'
  selection_traversal:
    TargetFilename|contains:
      - '../'
      - '..\'
  condition: selection_image and selection_traversal
falsepositives:
  - Rare legitimate project references using relative paths; scope to PCM600 hosts and review with engineering teams
level: medium
---
title: Permission Weakening or Service Manipulation Targeting PCM600 Paths
id: 4f7c9a15-82de-4c6a-a812-91bd0e7f5a90
status: experimental
description: Detects ACL changes, service control operations, or binary replacement activity referencing PCM600 paths that could prepare or follow privilege escalation.
references:
  - https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03
author: Security Arsenal
date: 2026/02/03
tags:
  - attack.privilege_escalation
  - attack.persistence
  - attack.t1543
  - attack.t1078
logsource:
  category: process_creation
  product: windows
detection:
  selection_tool:
    Image|contains:
      - 'icacls.exe'
      - 'cacls.exe'
      - 'sc.exe'
      - 'regsvr32.exe'
      - 'takeown.exe'
  selection_target:
    CommandLine|contains: 'PCM600'
  condition: selection_tool and selection_target
falsepositives:
  - ABB installers, upgrades, and approved change windows; correlate with CMDB tickets and vendor maintenance activity
level: high
KQL — Microsoft Sentinel / Defender
// Hunt for suspicious process lineage and traversal indicators on PCM600 engineering hosts.
// Recommended scope: first run against a device group containing known PCM600/OT engineering workstations.
let pcm600Hosts =
    DeviceInfo
    | where DeviceName has_any ("eng", "ot", "substation", "relay", "pcm600")
    | summarize by DeviceId;
DeviceProcessEvents
| where DeviceId in (pcm600Hosts)
| where InitiatingProcessCommandLine has_any ("PCM600", "Scheduler Service")
   or ProcessCommandLine has_any ("PCM600", "../", "..\\")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe", "mshta.exe", "rundll32.exe", "sc.exe", "icacls.exe", "takeown.exe")
   or ProcessCommandLine has_any ("../", "..\\")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256, FolderPath
| order by TimeGenerated desc;
// Correlate file writes by PCM600-related processes to sensitive destinations.
DeviceFileEvents
| where DeviceId in (pcm600Hosts)
| where InitiatingProcessCommandLine has "PCM600" or InitiatingProcessFolderPath has "PCM600"
| where FolderPath has_any ("Windows", "System32", "Program Files", "ProgramData", "Startup", "Scheduler")
   or FileName has_any (".exe", ".dll", ".bat", ".ps1", ".ini", ".cid", ".scd")
| project TimeGenerated, DeviceName, InitiatingProcessAccountName, InitiatingProcessFileName, InitiatingProcessCommandLine, ActionType, FolderPath, FileName, SHA256
| order by TimeGenerated desc;
// If CEF/Syslog is used for OT network sensors, look for engineering host sessions to substation segments after local process activity.
CommonSecurityLog
| where DeviceVendor has_any ("ABB", "Firewall", "EDR") or Message has "PCM600"
| where Message has_any ("PCM600", "../", "scheduler")
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceVendor, DeviceProduct, Message
| order by TimeGenerated desc
VQL — Velociraptor
-- Velociraptor hunt for PCM600-related processes, suspicious children, and exposed network sessions.
-- Run against endpoints labeled as engineering workstations, OT jump hosts, or substation maintenance assets.
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ 'PCM600|Scheduler Service'
   OR Exe =~ 'PCM600'
   OR (Name =~ 'cmd|powershell|pwsh|wscript|cscript|mshta|rundll32|sc|icacls|takeown'
       AND CommandLine =~ 'PCM600|ProgramData|AppData|Temp|../')

-- Enumerate current TCP/UDP listeners and established sessions from hosts running PCM600 components.
SELECT Pid, Name, LocalAddr, LocalPort, RemoteAddr, RemotePort, State, Process
FROM netstat()
WHERE Process =~ 'PCM600'
   OR Name =~ 'PCM600'
   OR State =~ 'ESTABLISHED|LISTEN'
PowerShell
# Audit PCM600 exposure, service context, weak ACLs, and suspicious local artifacts.
# Run as Administrator on engineering workstations. Default mode is audit-only.
param(
  [switch]$ApplyHardening,
  [string]$ReportPath = (Join-Path $env:TEMP 'PCM600_Security_Audit.csv')
)

$results = New-Object System.Collections.Generic.List[object]

function Add-Result {
  param([string]$Area,[string]$Status,[string]$Detail,[string]$Recommendation)
  $script:results.Add([pscustomobject]@{
    Time = Get-Date -Format o
    Host = $env:COMPUTERNAME
    Area = $Area
    Status = $Status
    Detail = $Detail
    Recommendation = $Recommendation
  })
}

# Installed version discovery from uninstall registry hives.
$uninstallRoots = @(
  'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
  'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$apps = Get-ItemProperty $uninstallRoots -ErrorAction SilentlyContinue | Where-Object { $_.DisplayName -match 'PCM600|Protection and Control IED Manager' }
if (-not $apps) {
  Add-Result 'Inventory' 'Info' 'No PCM600 uninstall entry found.' 'Confirm whether this host is in scope before applying controls.'
} else {
  foreach ($app in $apps) {
    $version = [version]($app.DisplayVersion -replace '[^0-9\.]', '')
    if ($version -le [version]'2.14') {
      Add-Result 'Inventory' 'Vulnerable' "Detected $($app.DisplayName) version $($app.DisplayVersion)." 'Plan upgrade to the vendor-fixed PCM600 release and verify via CISA ICSA-26-274-03 and ABB advisory.'
    } else {
      Add-Result 'Inventory' 'Review' "Detected $($app.DisplayName) version $($app.DisplayVersion)." 'Confirm this version is explicitly listed as fixed by ABB for CVE-2026-15952 and CVE-2026-15953.'
    }
  }
}

# Service discovery and account context.
$services = Get-CimInstance Win32_Service -ErrorAction SilentlyContinue | Where-Object { $_.Name -match 'PCM600|Scheduler' -or $_.PathName -match 'PCM600' }
foreach ($svc in $services) {
  $riskyAccount = $svc.StartName -match 'LocalSystem|NetworkService|Administrator|Domain Admin'
  $state = if ($riskyAccount) { 'Review' } else { 'Info' }
  Add-Result 'Service' $state "Service $($svc.Name) runs as $($svc.StartName); state $($svc.State); path $($svc.PathName)." 'Use least privilege, restrict service logon rights, and confirm the binary path ACLs are not user-writable.'

  if ($svc.PathName) {
    $exe = ($svc.PathName -split '"')[1]
    if ($exe -and (Test-Path $exe)) {
      $dir = Split-Path $exe -Parent
      $acl = Get-Acl $dir -ErrorAction SilentlyContinue
      $weak = $acl.Access | Where-Object { $_.IdentityReference -match 'Everyone|BUILTIN\Users|Authenticated Users|DOMAIN\Domain Users' -and $_.FileSystemRights -match 'Write|Modify|FullControl' }
      if ($weak) {
        Add-Result 'ACL' 'Weak' "Directory $dir grants write-like rights to non-admin identities." 'Remove write/modify for standard users from service binary, configuration, and scheduler-working directories.'
        if ($ApplyHardening) {
          icacls $dir /remove:g 'BUILTIN\Users' 'Authenticated Users' 'Everyone' 2>$null | Out-Null
          Add-Result 'ACL' 'Hardened' "Attempted removal of broad write grants on $dir." 'Re-test PCM600 functions after change and document rollback steps.'
        }
      } else {
        Add-Result 'ACL' 'OK' "No broad write-like ACE found on $dir." 'Keep monitoring for ACL drift during upgrades and vendor maintenance.'
      }
    }
  }
}

# Local artifact review: recent writes and suspicious persistence touching PCM600 paths.
$roots = @($env:ProgramFiles, ${env:ProgramFiles(x86)}, $env:ProgramData, $env:APPDATA, $env:TEMP) | Where-Object { $_ }
$recent = foreach ($root in $roots) {
  if (Test-Path $root) {
    Get-ChildItem $root -Recurse -ErrorAction SilentlyContinue -Force |
      Where-Object { $_.FullName -match 'PCM600' -and $_.LastWriteTime -gt (Get-Date).AddDays(-14) } |
      Select-Object -First 200
  }
}
foreach ($item in $recent) {
  Add-Result 'Artifact' 'Review' "Recently modified PCM600-related file: $($item.FullName)" 'Validate against approved engineering change records and check hash reputation.'
}

$tasks = Get-ScheduledTask -ErrorAction SilentlyContinue | Where-Object { ($_.TaskPath + $_.TaskName) -match 'PCM600|ABB|Scheduler' }
foreach ($task in $tasks) {
  Add-Result 'Persistence' 'Review' "Scheduled task $($task.TaskPath)$($task.TaskName) may be related to ABB/PCM600/Scheduler." 'Confirm owner, action executable, and whether it is required for operations.'
}

$results | Export-Csv -NoTypeInformation -Path $ReportPath
$results | Format-Table -AutoSize
Write-Host "Report written to $ReportPath"
if ($results | Where-Object { $_.Status -in @('Vulnerable','Weak') }) { exit 2 } else { exit 0 }

Remediation and Hardening

  1. Inventory immediately. Identify every workstation, laptop, jump host, virtual desktop, test bench, and vendor-managed asset running PCM600. Include spare engineering laptops and images used for outage work; unmanaged copies are common in power environments.

  2. Upgrade affected versions. PCM600 2.14 and earlier are in scope. Obtain the corrected release directly from ABB and validate the fixed-version statement against CISA ICSA-26-274-03 and the vendor CSAF advisory. Do not assume a hotfix from an email or third-party portal is authentic; verify hashes and signatures where ABB provides them. Reference: https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03

  3. If patching is delayed by outage windows, isolate and constrain. Place PCM600 hosts in a controlled OT engineering zone, block direct Internet access, restrict SMB/RDP/WinRM to approved management paths, require MFA and PAW or jump-host access, and prevent ordinary corporate users from reaching engineering file shares. Disable the Scheduler Service only if ABB and operations confirm it is not required; otherwise reduce its privilege and monitor it heavily.

  4. Enforce least privilege. Review the PCM600 Scheduler Service account, service DACL, binary path, working directory, and any directories used for project import/export. Remove write and modify rights for Everyone, Authenticated Users, Domain Users, and broad local groups from service executables, DLL directories, configuration stores, and task-working folders. Preserve SYSTEM and Administrators as required after testing.

  5. Constrain file overwrite paths. Ensure project repositories, relay configuration exports, firmware staging folders, and reports reside in ACL-controlled locations with auditing enabled. Where supported, redirect temporary and working folders away from user-writable world-readable paths. Watch for junctions, symbolic links, and synchronization tools that can turn a safe path into an attacker-influenced path.

  6. Add monitoring before the change window. Deploy the process-lineage and ACL-drift detections above to known PCM600 assets. Alert on new local administrators, new services, scheduled tasks, changes under PCM600 directories, and writes from PCM600 processes into Windows, Program Files, startup locations, or OT configuration shares.

  7. Coordinate with operations. For utilities, remediation should be tied to change management, relay maintenance windows, and validation of protection settings after upgrade. Record pre- and post-patch hashes for critical configuration files, and confirm that no unexpected IED setting changes occurred around the maintenance period.

  8. Validate exposure externally. If vendors or integrators access PCM600 hosts remotely, review their accounts, session recording, source IP restrictions, and credential rotation. A local privilege escalation is far more dangerous when an external support pathway already lands on the engineering host.

Executive Takeaways

Medium CVSS does not equal low consequence in substation and protection engineering environments. ABB PCM600 sits close to the configuration plane for protective relays and control devices, so privilege escalation or file overwrite can translate into misoperation risk, delayed restoration, or unsafe settings. Prioritize inventory, vendor-verified upgrade, least-privilege service configuration, ACL hardening, and focused behavioral monitoring on engineering endpoints. If exploitation status changes, especially KEV addition or public exploit code, escalate from planned remediation to emergency change for exposed energy-sector assets.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.